Executive brief
A vulnerability in the error handling component of Oracle MySQL and MariaDB could allow a highly privileged user to gain unauthorized access to sensitive database information. To exploit this, an attacker must already have significant access to the underlying server infrastructure and requires a separate user to perform a specific action. While difficult to execute, a successful attack could lead to the exposure of all data stored within the database.
Technical details
This vulnerability exists in the Error Handling subcomponent of MySQL Server (versions 5.5.53, 5.6.34, 5.7.16 and earlier) and MariaDB. It is classified as a local vulnerability requiring high privileges (PR:H) and high attack complexity (AC:H). An attacker with existing logon access to the infrastructure where the server executes can exploit this flaw to gain unauthorized access to critical data. The exploit requires interaction from a person other than the attacker (UI:R). Patches were released in MySQL 5.5.54, 5.6.35, and 5.7.17, as well as MariaDB 10.0.29 and 10.1.21.
Affected products
- Oracle MySQL Server 5.5.53 and earlier, 5.6.34 and earlier, 5.7.16 and earlier
- MariaDB Foundation MariaDB 5.5.0 to 5.5.53, 10.0.0 to 10.0.28, 10.1.0 to 10.1.20
Timeline
- 2017-01-17: advisory: Oracle Critical Patch Update (CPU) January 2017 released
- 2017-01-19: patched: Debian released fixed mysql-5.5 packages (5.5.54-0+deb8u1)
- 2017-01-22: patched: Debian released fixed mariadb-10.0 packages (10.0.29-0+deb8u1)
- 2017-01-27: disclosed: NVD publication date
References
- http://www.debian.org/security/2017/dsa-3767
- http://www.debian.org/security/2017/dsa-3770
- http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html
- http://www.securityfocus.com/bid/95588
- http://www.securitytracker.com/id/1037640
- https://access.redhat.com/errata/RHSA-2017:2192
- https://access.redhat.com/errata/RHSA-2017:2787