peter bassill · operator
$ cve CVE-2016-6662 JSON

CVE-2016-6662 EXPLOIT

9.8
CRITICAL · CVSS 3.0 · EPSS 67.7% (pctl 99)

Patch early

A public exploit exists.

Description

Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0, and 5.7.x before 5.7.14-7 allow local users to create arbitrary configurations and bypass certain protection mechanisms by setting general_log_file to a my.cnf configuration. NOTE: this can be leveraged to execute arbitrary code with root privileges by setting malloc_lib. NOTE: the affected MySQL version information is from Oracle's October 2016 CPU. Oracle has not commented on third-party claims that the issue was silently patched in MySQL 5.5.52, 5.6.33, and 5.7.15.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS67.73% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2016-09-20
Last modified2026-06-17

Affected (12)

VendorProduct
debiandebian linux
mariadbmariadb
oraclemysql
perconapercona server
redhatenterprise linux
redhatenterprise linux desktop
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server eus
redhatenterprise linux server tus
redhatenterprise linux workstation
redhatopenstack

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD