Vigil@nce - MySQL: two vulnerabilities
November 2016 by Vigil@nce
This bulletin was written by Vigil@nce : https://vigilance.fr/offer
SYNTHESIS OF THE VULNERABILITY
An attacker can use several vulnerabilities of MySQL.
Impacted products: MariaDB precise, MySQL Community, MySQL
Enterprise, XtraDB Cluster.
Severity: 2/4.
Creation date: 23/09/2016.
Revision date: 23/09/2016.
DESCRIPTION OF THE VULNERABILITY
Several vulnerabilities were announced in MySQL.
An attacker can bypass security features via the command REPAIR
TABLE, in order to escalate his privileges. [severity:2/4;
1624397, 24388746]
An unknown vulnerability was announced via symbolic links.
[severity:2/4; 1624449]
ACCESS TO THE COMPLETE VIGIL@NCE BULLETIN
https://vigilance.fr/vulnerability/MySQL-two-vulnerabilities-20685