Arbitrary command execution in Oracle Linux - CVE-2016-6662

 

Arbitrary command execution in Oracle Linux - CVE-2016-6662

Published: October 12, 2016 / Updated: September 14, 2018


Vulnerability identifier: #VU946
CSH Severity: High
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-6662
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows an administrative user to execute arbitrary command on the target system.
The weakness exists due to insufficient access control that allows a malicious user to execute arbitrary command with root privileges that may lead to complete system compromise.
Successful exploitation of the vulnerability results in arbitrary code excution on the vulnerable system.

Affected software


Oracle Linux
SUSE Linux
Ubuntu
Slackware Linux
Fedora
mariadb (Alpine package)
mariadb-galera (Red Hat package)
community-mysql
mariadb
Red Hat OpenStack

How to mitigate CVE-2016-6662


mariadb (Alpine package) - update to 5.5.51-r0
mariadb-galera (Red Hat package) - addressed in versions 5.5.42-1.1.el6ost, 5.5.42-1.2.el7ost
community-mysql - update to 5.7.15-1.fc24
mariadb - update to 10.0.27-1.fc23

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins