Scientific Linux Security Update : mariadb on SL7.x x86_64 (20170801)

high Nessus Plugin ID 102648

Synopsis

The remote Scientific Linux host is missing one or more security updates.

Description

The following packages have been upgraded to a later upstream version:
mariadb (5.5.56).

Security Fix(es) :

- It was discovered that the mysql and mysqldump tools did not correctly handle database and table names containing newline characters. A database user with privileges to create databases or tables could cause the mysql command to execute arbitrary shell or SQL commands while restoring database backup created using the mysqldump tool. (CVE-2016-5483, CVE-2017-3600)

- A flaw was found in the way the mysqld_safe script handled creation of error log file. The mysql operating system user could use this flaw to escalate their privileges to root. (CVE-2016-5617, CVE-2016-6664)

- Multiple flaws were found in the way the MySQL init script handled initialization of the database data directory and permission setting on the error log file.
The mysql operating system user could use these flaws to escalate their privileges to root. (CVE-2017-3265)

- It was discovered that the mysqld_safe script honored the ledir option value set in a MySQL configuration file. A user able to modify one of the MySQL configuration files could use this flaw to escalate their privileges to root. (CVE-2017-3291)

- Multiple flaws were found in the way the mysqld_safe script handled creation of error log file. The mysql operating system user could use these flaws to escalate their privileges to root. (CVE-2017-3312)

- A flaw was found in the way MySQL client library (libmysqlclient) handled prepared statements when server connection was lost. A malicious server or a man-in-the-middle attacker could possibly use this flaw to crash an application using libmysqlclient.
(CVE-2017-3302)

(CVE-2017-3238, CVE-2017-3243, CVE-2017-3244, CVE-2017-3258, CVE-2017-3308, CVE-2017-3309, CVE-2017-3313, CVE-2017-3317, CVE-2017-3318, CVE-2017-3453, CVE-2017-3456, CVE-2017-3464)

Solution

Update the affected packages.

See Also

http://www.nessus.org/u?61a09e21

Plugin Details

Severity: High

ID: 102648

File Name: sl_20170801_mariadb_on_SL7_x.nasl

Version: 3.8

Type: local

Agent: unix

Published: 8/22/2017

Updated: 1/14/2021

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.4

CVSS v2

Risk Factor: Medium

Base Score: 6.9

Temporal Score: 6

Vector: CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C

CVSS v3

Risk Factor: High

Base Score: 7.7

Temporal Score: 7.4

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:fermilab:scientific_linux:mariadb, p-cpe:/a:fermilab:scientific_linux:mariadb-bench, p-cpe:/a:fermilab:scientific_linux:mariadb-debuginfo, p-cpe:/a:fermilab:scientific_linux:mariadb-devel, p-cpe:/a:fermilab:scientific_linux:mariadb-embedded, p-cpe:/a:fermilab:scientific_linux:mariadb-embedded-devel, p-cpe:/a:fermilab:scientific_linux:mariadb-libs, p-cpe:/a:fermilab:scientific_linux:mariadb-server, p-cpe:/a:fermilab:scientific_linux:mariadb-test, x-cpe:/o:fermilab:scientific_linux

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 8/1/2017

Vulnerability Publication Date: 10/25/2016

Reference Information

CVE: CVE-2016-5483, CVE-2016-5617, CVE-2016-6664, CVE-2017-3238, CVE-2017-3243, CVE-2017-3244, CVE-2017-3258, CVE-2017-3265, CVE-2017-3291, CVE-2017-3302, CVE-2017-3308, CVE-2017-3309, CVE-2017-3312, CVE-2017-3313, CVE-2017-3317, CVE-2017-3318, CVE-2017-3453, CVE-2017-3456, CVE-2017-3464, CVE-2017-3600