CVE-2016-0646

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect availability via vectors related to DML.

References

http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00035.html

http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00053.html

http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00033.html

http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00034.html

http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00051.html

http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00053.html

http://rhn.redhat.com/errata/RHSA-2016-0705.html

http://rhn.redhat.com/errata/RHSA-2016-1480.html

http://rhn.redhat.com/errata/RHSA-2016-1481.html

http://rhn.redhat.com/errata/RHSA-2016-1602.html

http://www.debian.org/security/2016/dsa-3557

http://www.debian.org/security/2016/dsa-3595

http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html

http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html

http://www.securityfocus.com/bid/86436

http://www.securitytracker.com/id/1035606

http://www.ubuntu.com/usn/USN-2953-1

http://www-01.ibm.com/support/docview.wss?uid=isg3T1024168

https://access.redhat.com/errata/RHSA-2016:1132

https://mariadb.com/kb/en/mariadb/mariadb-10024-release-notes/

https://mariadb.com/kb/en/mariadb/mariadb-10112-release-notes/

https://mariadb.com/kb/en/mariadb/mariadb-5548-release-notes/

Details

Source: MITRE

Published: 2016-04-21

Updated: 2019-12-27

Risk Information

CVSS v2

Base Score: 4

Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 8

Severity: MEDIUM

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Impact Score: 3.6

Exploitability Score: 1.8

Severity: MEDIUM

Tenable Plugins

View all (30 total)

IDNameProductFamilySeverity
125007EulerOS Virtualization 3.0.1.0 : mariadb (EulerOS-SA-2019-1554)NessusHuawei Local Security Checks
high
99798EulerOS 2.0 SP1 : mariadb (EulerOS-SA-2016-1035)NessusHuawei Local Security Checks
medium
93829MariaDB 10.1.x < 10.1.12 Multiple VulnerabilitiesNessusDatabases
medium
93828MariaDB 10.0.x < 10.0.24 Multiple VulnerabilitiesNessusDatabases
medium
93159SUSE SLED12 / SLES12 Security Update : mariadb (SUSE-SU-2016:1620-1)NessusSuSE Local Security Checks
medium
93158SUSE SLED12 / SLES12 Security Update : mariadb (SUSE-SU-2016:1619-1)NessusSuSE Local Security Checks
medium
93016Amazon Linux AMI : mysql55 (ALAS-2016-738)NessusAmazon Linux Local Security Checks
high
92996Scientific Linux Security Update : mariadb on SL7.x x86_64 (20160811)NessusScientific Linux Local Security Checks
high
92950CentOS 7 : mariadb (CESA-2016:1602)NessusCentOS Local Security Checks
high
92938RHEL 7 : mariadb (RHSA-2016:1602)NessusRed Hat Local Security Checks
high
92934Oracle Linux 7 : mariadb (ELSA-2016-1602)NessusOracle Linux Local Security Checks
high
91871openSUSE Security Update : mariadb (openSUSE-2016-780)NessusSuSE Local Security Checks
medium
91794openSUSE Security Update : mariadb (openSUSE-2016-761)NessusSuSE Local Security Checks
medium
91474Debian DSA-3595-1 : mariadb-10.0 - security updateNessusDebian Local Security Checks
medium
91277openSUSE Security Update : mysql-community-server (openSUSE-2016-607)NessusSuSE Local Security Checks
critical
91121SUSE SLES11 Security Update : mysql (SUSE-SU-2016:1279-1)NessusSuSE Local Security Checks
medium
90847FreeBSD : MySQL -- multiple vulnerabilities (8c2b2f11-0ebe-11e6-b55e-b499baebfeaf)NessusFreeBSD Local Security Checks
critical
90833Oracle MySQL 5.7.x < 5.7.11 Multiple Vulnerabilities (April 2016 CPU) (July 2016 CPU)NessusDatabases
medium
90831Oracle MySQL 5.6.x < 5.6.29 Multiple Vulnerabilities (April 2016 CPU)NessusDatabases
medium
90829Oracle MySQL 5.5.x < 5.5.48 Multiple Vulnerabilities (April 2016 CPU)NessusDatabases
medium
90804Debian DLA-447-1 : mysql-5.5 security updateNessusDebian Local Security Checks
medium
90724Debian DSA-3557-1 : mysql-5.5 - security updateNessusDebian Local Security Checks
medium
90678Ubuntu 12.04 LTS / 14.04 LTS / 15.10 : mysql-5.5, mysql-5.6 vulnerabilities (USN-2953-1)NessusUbuntu Local Security Checks
critical
9259Oracle MySQL 5.5.x < 5.5.48 / 5.6.x < 5.6.29 / 5.7.x < 5.7.11 Multiple VulnerabilitiesNessus Network MonitorDatabase
medium
9254Oracle MySQL 5.5.x < 5.5.48 Multiple DoSNessus Network MonitorDatabase
medium
9238MySQL 5.6.x < 5.6.29 Multiple DoSNessus Network MonitorDatabase
medium
89056MySQL 5.7.x < 5.7.11 Multiple VulnerabilitiesNessusDatabases
medium
89055MySQL 5.6.x < 5.6.29 Multiple VulnerabilitiesNessusDatabases
medium
89054MySQL 5.5.x < 5.5.48 Multiple VulnerabilitiesNessusDatabases
medium
87728MariaDB 5.5 < 5.5.48 Multiple VulnerabilitiesNessusDatabases
medium