MGASA-2016-0371
Dashboard / Vulnerabilities / MGASA-2016-0371
MGASA-2016-0371
Summary: Updated mariadb packages fix security vulnerabilities
Details: A race condition was found in the way MariaDB performed MyISAM engine table repair. A database user with shell access to the server running mysqld could use this flaw to change permissions of arbitrary files writable by the mysql system user (CVE-2016-6663). This update fixes several vulnerabilities in the MariaDB database server. Information about these flaws can be found on the Oracle Critical Patch Update Advisory page, listed in the References section (CVE-2016-3492, CVE-2016-5584, CVE-2016-5616, CVE-2016-5624, CVE-2016-5626, CVE-2016-5629, CVE-2016-7440, CVE-2016-8283).
References: https://advisories.mageia.org/MGASA-2016-0371.html, https://bugs.mageia.org/show_bug.cgi?id=19693, https://mariadb.com/kb/en/mariadb/mariadb-10028-release-notes/, http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html, https://rhn.redhat.com/errata/RHSA-2016-2595.html
Affected packages
Package
Name: mariadb
Purl: pkg:rpm/mageia/mariadb?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
