Executive brief
A vulnerability in the MyISAM storage engine of Oracle MySQL and MariaDB could allow a local user with low-level access to the server's host system to compromise the database. If successfully exploited, an attacker could gain unauthorized access to sensitive business data or all information stored within the database. While the flaw is difficult to exploit, it poses a risk to data confidentiality for systems where multiple users have local login access.
Technical details
This vulnerability affects the MyISAM storage engine subcomponent of MySQL Server and MariaDB. It is characterized as a difficult-to-exploit flaw that requires the attacker to have local logon credentials to the infrastructure where the database server is executing. Successful exploitation allows a low-privileged user to bypass certain security restrictions to impact the confidentiality of the data. The vulnerability has been addressed in MySQL versions 5.5.54, 5.6.35, and 5.7.17, as well as MariaDB 10.0.30, 10.1.22, and 10.2.5. NIST classifies this under NVD-CWE-noinfo due to lack of specific root cause details in the vendor advisory.
Affected products
- Oracle MySQL Server 5.5.53 and earlier, 5.6.34 and earlier, 5.7.16 and earlier
- MariaDB Foundation MariaDB 5.5.0 to 5.5.54, 10.0.0 to 10.0.29, 10.1.0 to 10.1.21, 10.2.0 to 10.2.4
Timeline
- 2017-01-19: advisory: Debian released DSA 3767-1 for mysql-5.5
- 2017-01-27: disclosed: Initial NVD publication date
- 2017-03-14: advisory: Debian released DSA 3809-1 for mariadb-10.0
References
- http://www.debian.org/security/2017/dsa-3767
- http://www.debian.org/security/2017/dsa-3809
- http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html
- http://www.securityfocus.com/bid/95527
- http://www.securitytracker.com/id/1037640
- https://access.redhat.com/errata/RHSA-2017:2192
- https://access.redhat.com/errata/RHSA-2017:2787