Information disclosure in MariaDB - CVE-2016-5584

 

Information disclosure in MariaDB - CVE-2016-5584

Published: October 25, 2016 / Updated: July 28, 2020


Vulnerability identifier: #VU32224
CSH Severity: Low
CVSS v4: 5.9 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-5584
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote privileged user to gain access to sensitive information.

Unspecified vulnerability in Oracle MySQL 5.5.52 and earlier, 5.6.33 and earlier, and 5.7.15 and earlier allows remote administrators to affect confidentiality via vectors related to Server: Security: Encryption.


Affected software

MariaDB
mariadb (Alpine package)
SUSE Linux

How to mitigate CVE-2016-5584

Install update from vendor's website.

MariaDB - update to 5.5.53
mariadb (Alpine package) - update to 10.1.19-r0

External References

Related Security Bulletins