Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.4.2017.0412.1
Category:SuSE Local Security Checks
Title:SUSE: Security Advisory (SUSE-SU-2017:0412-1)
Summary:The remote host is missing an update for the 'mariadb' package(s) announced via the SUSE-SU-2017:0412-1 advisory.
Description:Summary:
The remote host is missing an update for the 'mariadb' package(s) announced via the SUSE-SU-2017:0412-1 advisory.

Vulnerability Insight:
This mariadb version update to 10.0.29 fixes the following issues:

- CVE-2017-3318: unspecified vulnerability affecting Error Handling (bsc#1020896)
- CVE-2017-3317: unspecified vulnerability affecting Logging (bsc#1020894)
- CVE-2017-3312: insecure error log file handling in mysqld_safe, incomplete CVE-2016-6664 (bsc#1020873)
- CVE-2017-3291: unrestricted mysqld_safe's ledir (bsc#1020884)
- CVE-2017-3265: unsafe chmod/chown use in init script (bsc#1020885)
- CVE-2017-3258: unspecified vulnerability in the DDL component (bsc#1020875)
- CVE-2017-3257: unspecified vulnerability affecting InnoDB (bsc#1020878)
- CVE-2017-3244: unspecified vulnerability affecing the DML component (bsc#1020877)
- CVE-2017-3243: unspecified vulnerability affecting the Charsets component (bsc#1020891)
- CVE-2017-3238: unspecified vulnerability affecting the Optimizer component (bsc#1020882)
- CVE-2016-6664: Root Privilege Escalation (bsc#1008253)
- Applications using the client library for MySQL (libmysqlclient.so) had a use-after-free issue that could cause the applications to crash (bsc#1022428)

- notable changes:
* XtraDB updated to 5.6.34-79.1
* TokuDB updated to 5.6.34-79.1
* Innodb updated to 5.6.35
* Performance Schema updated to 5.6.35

Release notes and changelog:
* [links moved to references]

Affected Software/OS:
'mariadb' package(s) on SUSE Linux Enterprise Desktop 12-SP1, SUSE Linux Enterprise Desktop 12-SP2, SUSE Linux Enterprise Server 12-SP1, SUSE Linux Enterprise Server 12-SP2, SUSE Linux Enterprise Server for Raspberry Pi 12-SP2, SUSE Linux Enterprise Server for SAP Applications 12-SP1, SUSE Linux Enterprise Server for SAP Applications 12-SP2.

Solution:
Please install the updated package(s).

CVSS Score:
6.9

CVSS Vector:
AV:L/AC:M/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2016-6664
BugTraq ID: 93612
http://www.securityfocus.com/bid/93612
Bugtraq: 20161104 MySQL / MariaDB / PerconaDB - Root Privilege Escalation Exploit ( CVE-2016-6664 / CVE-2016-5617 ) (Google Search)
http://www.securityfocus.com/archive/1/539695/100/0/threaded
Debian Security Information: DSA-3770 (Google Search)
http://www.debian.org/security/2017/dsa-3770
https://www.exploit-db.com/exploits/40679/
http://seclists.org/fulldisclosure/2016/Nov/4
https://security.gentoo.org/glsa/201702-18
http://legalhackers.com/advisories/MySQL-Maria-Percona-RootPrivEsc-CVE-2016-6664-5617-Exploit.html
http://packetstormsecurity.com/files/139491/MySQL-MariaDB-PerconaDB-Root-Privilege-Escalation.html
RedHat Security Advisories: RHSA-2016:2130
http://rhn.redhat.com/errata/RHSA-2016-2130.html
RedHat Security Advisories: RHSA-2016:2749
http://rhn.redhat.com/errata/RHSA-2016-2749.html
RedHat Security Advisories: RHSA-2017:2192
https://access.redhat.com/errata/RHSA-2017:2192
RedHat Security Advisories: RHSA-2018:0279
https://access.redhat.com/errata/RHSA-2018:0279
RedHat Security Advisories: RHSA-2018:0574
https://access.redhat.com/errata/RHSA-2018:0574
Common Vulnerability Exposure (CVE) ID: CVE-2017-3238
BugTraq ID: 95571
http://www.securityfocus.com/bid/95571
Debian Security Information: DSA-3767 (Google Search)
http://www.debian.org/security/2017/dsa-3767
https://security.gentoo.org/glsa/201702-17
RedHat Security Advisories: RHSA-2017:2787
https://access.redhat.com/errata/RHSA-2017:2787
RedHat Security Advisories: RHSA-2017:2886
https://access.redhat.com/errata/RHSA-2017:2886
http://www.securitytracker.com/id/1037640
Common Vulnerability Exposure (CVE) ID: CVE-2017-3243
BugTraq ID: 95538
http://www.securityfocus.com/bid/95538
Common Vulnerability Exposure (CVE) ID: CVE-2017-3244
BugTraq ID: 95565
http://www.securityfocus.com/bid/95565
Common Vulnerability Exposure (CVE) ID: CVE-2017-3257
BugTraq ID: 95589
http://www.securityfocus.com/bid/95589
Common Vulnerability Exposure (CVE) ID: CVE-2017-3258
BugTraq ID: 95560
http://www.securityfocus.com/bid/95560
Common Vulnerability Exposure (CVE) ID: CVE-2017-3265
BugTraq ID: 95520
http://www.securityfocus.com/bid/95520
Common Vulnerability Exposure (CVE) ID: CVE-2017-3291
BugTraq ID: 95501
http://www.securityfocus.com/bid/95501
Common Vulnerability Exposure (CVE) ID: CVE-2017-3312
BugTraq ID: 95491
http://www.securityfocus.com/bid/95491
Common Vulnerability Exposure (CVE) ID: CVE-2017-3317
BugTraq ID: 95585
http://www.securityfocus.com/bid/95585
Common Vulnerability Exposure (CVE) ID: CVE-2017-3318
BugTraq ID: 95588
http://www.securityfocus.com/bid/95588
CopyrightCopyright (C) 2021 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.