CVE-2016-0643

low
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows local users to affect confidentiality via vectors related to DML.

References

http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00035.html

http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00053.html

http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00033.html

http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00034.html

http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00051.html

http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00053.html

http://rhn.redhat.com/errata/RHSA-2016-0705.html

http://rhn.redhat.com/errata/RHSA-2016-1480.html

http://rhn.redhat.com/errata/RHSA-2016-1481.html

http://rhn.redhat.com/errata/RHSA-2016-1602.html

http://www.debian.org/security/2016/dsa-3557

http://www.debian.org/security/2016/dsa-3595

http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html

http://www.securityfocus.com/bid/86486

http://www.securitytracker.com/id/1035606

http://www.ubuntu.com/usn/USN-2953-1

http://www.ubuntu.com/usn/USN-2954-1

http://www-01.ibm.com/support/docview.wss?uid=isg3T1024168

https://access.redhat.com/errata/RHSA-2016:1132

https://mariadb.com/kb/en/mariadb/mariadb-10025-release-notes/

https://mariadb.com/kb/en/mariadb/mariadb-10114-release-notes/

https://mariadb.com/kb/en/mariadb/mariadb-5549-release-notes/

Details

Source: MITRE

Published: 2016-04-21

Updated: 2019-04-22

Risk Information

CVSS v2

Base Score: 4

Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Impact Score: 2.9

Exploitability Score: 8

Severity: MEDIUM

CVSS v3

Base Score: 3.3

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Impact Score: 1.4

Exploitability Score: 1.8

Severity: LOW

Tenable Plugins

View all (32 total)

IDNameProductFamilySeverity
125007EulerOS Virtualization 3.0.1.0 : mariadb (EulerOS-SA-2019-1554)NessusHuawei Local Security Checks
high
99798EulerOS 2.0 SP1 : mariadb (EulerOS-SA-2016-1035)NessusHuawei Local Security Checks
medium
93616MariaDB 5.5.x < 5.5.49 Multiple VulnerabilitiesNessusDatabases
low
93159SUSE SLED12 / SLES12 Security Update : mariadb (SUSE-SU-2016:1620-1)NessusSuSE Local Security Checks
medium
93158SUSE SLED12 / SLES12 Security Update : mariadb (SUSE-SU-2016:1619-1)NessusSuSE Local Security Checks
medium
9482Oracle MySQL 5.5.x < 5.5.49 / 5.6.x < 5.6.30 / 5.7.x < 5.7.12 Multiple VulnerabilitiesNessus Network MonitorDatabase
critical
93016Amazon Linux AMI : mysql55 (ALAS-2016-738)NessusAmazon Linux Local Security Checks
high
92996Scientific Linux Security Update : mariadb on SL7.x x86_64 (20160811)NessusScientific Linux Local Security Checks
high
92950CentOS 7 : mariadb (CESA-2016:1602)NessusCentOS Local Security Checks
high
92938RHEL 7 : mariadb (RHSA-2016:1602)NessusRed Hat Local Security Checks
high
92934Oracle Linux 7 : mariadb (ELSA-2016-1602)NessusOracle Linux Local Security Checks
high
92116Fedora 23 : community-mysql (2016-7c48036d73)NessusFedora Local Security Checks
critical
92063Fedora 22 : community-mysql (2016-1aaf308de4)NessusFedora Local Security Checks
critical
91871openSUSE Security Update : mariadb (openSUSE-2016-780)NessusSuSE Local Security Checks
medium
91794openSUSE Security Update : mariadb (openSUSE-2016-761)NessusSuSE Local Security Checks
medium
91766MariaDB 10.1.x < 10.1.14 Multiple VulnerabilitiesNessusDatabases
low
91765MariaDB 10.0.x < 10.0.25 Multiple VulnerabilitiesNessusDatabases
low
91474Debian DSA-3595-1 : mariadb-10.0 - security updateNessusDebian Local Security Checks
medium
91277openSUSE Security Update : mysql-community-server (openSUSE-2016-607)NessusSuSE Local Security Checks
critical
91239Amazon Linux AMI : mysql56 (ALAS-2016-701)NessusAmazon Linux Local Security Checks
critical
91121SUSE SLES11 Security Update : mysql (SUSE-SU-2016:1279-1)NessusSuSE Local Security Checks
medium
90847FreeBSD : MySQL -- multiple vulnerabilities (8c2b2f11-0ebe-11e6-b55e-b499baebfeaf)NessusFreeBSD Local Security Checks
critical
90834Oracle MySQL 5.7.x < 5.7.12 Multiple Vulnerabilities (RPM Check) (April 2016 CPU) (July 2016 CPU) (October 2017 CPU) (DROWN)NessusDatabases
critical
90832Oracle MySQL 5.6.x < 5.6.30 Multiple Vulnerabilities (April 2016 CPU) (July 2016 CPU) (DROWN)NessusDatabases
critical
90830Oracle MySQL 5.5.x < 5.5.49 Multiple Vulnerabilities (April 2016 CPU) (July 2016 CPU)NessusDatabases
low
90804Debian DLA-447-1 : mysql-5.5 security updateNessusDebian Local Security Checks
medium
90760Ubuntu 16.04 LTS : mysql-5.7 vulnerabilities (USN-2954-1)NessusUbuntu Local Security Checks
critical
90724Debian DSA-3557-1 : mysql-5.5 - security updateNessusDebian Local Security Checks
medium
90684MySQL 5.7.x < 5.7.12 Multiple Vulnerabilities (DROWN)NessusDatabases
critical
90683MySQL 5.6.x < 5.6.30 Multiple Vulnerabilities (DROWN)NessusDatabases
critical
90682MySQL 5.5.x < 5.5.49 Multiple VulnerabilitiesNessusDatabases
medium
90678Ubuntu 12.04 LTS / 14.04 LTS / 15.10 : mysql-5.5, mysql-5.6 vulnerabilities (USN-2953-1)NessusUbuntu Local Security Checks
critical