mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2, 5.6.x before 5.6.32-78-1, and 5.7.x before 5.7.14-8; and Percona XtraDB Cluster before 5.5.41-37.0, 5.6.x before 5.6.32-25.17, and 5.7.x before 5.7.14-26.17, when using file-based logging, allows local users with access to the mysql account to gain root privileges via a symlink attack on error logs and possibly other files.
[
{
"signature_type": "Function",
"source": "https://github.com/mariadb/server/commit/5fc1ba604e27b7d9eaa2977ef5b0c180f6f62565",
"target": {
"file": "storage/xtradb/handler/ha_innodb.cc",
"function": "wsrep_calc_row_hash"
},
"id": "CVE-2016-6664-2235861b",
"signature_version": "v1",
"digest": {
"function_hash": "326577626690167958606778565745841641029",
"length": 1075.0
},
"deprecated": false
},
{
"signature_type": "Function",
"source": "https://github.com/mariadb/server/commit/5fc1ba604e27b7d9eaa2977ef5b0c180f6f62565",
"target": {
"file": "storage/xtradb/handler/ha_innodb.cc",
"function": "wsrep_store_key_val_for_row"
},
"id": "CVE-2016-6664-76d7bb16",
"signature_version": "v1",
"digest": {
"function_hash": "175766638502419520218478376205151830061",
"length": 4678.0
},
"deprecated": false
},
{
"signature_type": "Line",
"source": "https://github.com/mariadb/server/commit/5fc1ba604e27b7d9eaa2977ef5b0c180f6f62565",
"target": {
"file": "storage/xtradb/handler/ha_innodb.cc"
},
"id": "CVE-2016-6664-d7841ca0",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"333910009814716899599761924093289489726",
"161392224999518567510718607174078569010",
"161097539754424727880941917296259394470",
"86950865214847603434991963376525204394",
"149603238303571009756227611135528613560",
"246754121958178494555659751381354980297",
"112180117738318881565344278433296106535",
"56934855970519006216491266214889014278",
"177233899003535037117533813868483428969",
"91781135331166554714959393998795539181",
"231826346572631787101747650932251996807",
"120129231197026531763378830534168927209",
"78750874032296690609296176761798461946",
"37466225183381131843040316628502534513",
"73966958620296014639090697993023755838",
"302517151867660583156292446738041253690",
"320251111942484271165771358375346713457",
"137617643939518963627606737565894291194"
]
},
"deprecated": false
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-6664.json"