Vulnerability Name:

CVE-2020-7221 (CCN-175717)

Assigned:2020-02-04
Published:2020-02-04
Updated:2021-07-21
Summary:mysql_install_db in MariaDB 10.4.7 through 10.4.11 allows privilege escalation from the mysql user account to root because chown and chmod are performed unsafely, as demonstrated by a symlink attack on a chmod 04755 of auth_pam_tool_dir/auth_pam_tool.
Note: this does not affect the Oracle MySQL product, which implements mysql_install_db differently.
CVSS v3 Severity:7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
6.9 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
7.8 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
6.9 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
6.8 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-269
Vulnerability Consequences:Gain Privileges
References:Source: MITRE
Type: CNA
CVE-2020-7221

Source: MISC
Type: Exploit, Issue Tracking, Third Party Advisory
https://bugzilla.suse.com/show_bug.cgi?id=1160868

Source: XF
Type: UNKNOWN
mariadb-cve20207221-priv-esc(175717)

Source: CONFIRM
Type: Third Party Advisory
https://github.com/MariaDB/server/commit/9d18b6246755472c8324bf3e20e234e08ac45618

Source: CCN
Type: MariaDB Web site
MariaDB

Source: CCN
Type: oss-sec Mailing List, Tue, 4 Feb 2020 11:26:04 +0100
CVE-2020-7221: mariadb: possible local mysql to root user exploit in mysql_install_db script setting permissions of /usr/lib64/mysql/plugin/auth_pam_tool_dir/auth_pam_tool

Source: MISC
Type: Exploit, Mailing List, Third Party Advisory
https://seclists.org/oss-sec/2020/q1/55

Source: CCN
Type: oss-sec Mailing List, Tue, 4 Feb 2020 13:27:11 +0100
Re: CVE-2020-7221: mariadb: possible local mysql to root user exploit in mysql_install_db script setting permissions of /usr/lib64/mysql/plugin/auth_pam_tool_dir/auth_pam_tool

Vulnerable Configuration:Configuration 1:
  • cpe:/a:mariadb:mariadb:*:*:*:*:*:*:*:* (Version >= 10.4.7 and <= 10.4.11)

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20207221
    V
    CVE-2020-7221
    2022-09-02
    oval:org.opensuse.security:def:3491
    P
    ft2demos-2.6.3-7.15.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:95121
    P
    libmariadbd-devel-10.6.7-150400.1.4 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:112683
    P
    libmariadbd-devel-10.6.4-2.1 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:106162
    P
    libmariadbd-devel-10.6.4-2.1 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:1632
    P
    Security update for xen (Moderate)
    2021-09-18
    oval:org.opensuse.security:def:2253
    P
    libmariadbd-devel-10.5.8-1.5 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:66888
    P
    Security update for the Linux Kernel (Important)
    2021-08-10
    oval:org.opensuse.security:def:63342
    P
    libmariadbd-devel-10.5.8-1.5 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:100932
    P
    libmarkdown2-2.2.4-1.41 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:70244
    P
    Security update for caribou (Important)
    2021-06-17
    oval:org.opensuse.security:def:66796
    P
    Security update for slurm (Important)
    2021-05-31
    oval:org.opensuse.security:def:73579
    P
    Security update for OpenIPMI (Moderate)
    2021-04-01
    oval:org.opensuse.security:def:94219
    P
    (Moderate)
    2021-02-22
    oval:org.opensuse.security:def:2188
    P
    libmariadbd-devel-10.4.13-1.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:117156
    P
    libmariadbd-devel-10.4.13-1.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63277
    P
    libmariadbd-devel-10.4.13-1.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107598
    P
    libmariadbd-devel-10.4.13-1.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:50019
    P
    libwsman-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50073
    P
    libmariadbd-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73461
    P
    libxcb-render0-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:70139
    P
    texlive-12many on GA media (Moderate)
    2020-12-01
    oval:com.ubuntu.xenial:def:202072210000000
    V
    CVE-2020-7221 on Ubuntu 16.04 LTS (xenial) - medium.
    2020-02-04
    BACK
    mariadb mariadb *