Nov
02
2016
--

Percona responds to CVE-2016-6663 and CVE-2016-6664

CVE-2016-6663 and CVE-2016-6664

CVE-2016-6663 and CVE-2016-6664Percona has addressed CVE-2016-6663 and CVE-2016-6664 in releases of Percona Server for MySQL and Percona XtraDB Cluster.

Percona is happy to announce that the following vulnerabilities are fixed in current releases of Percona Server for MySQL and Percona XtraDB Cluster:

  • CVE-2016-6663: allows a local system user with access to the affected database in the context of a low-privileged account (CREATE/INSERT/SELECT grants) to escalate their privileges and execute arbitrary code as the database system user (typically “mysql”).
  • CVE-2016-6664: can let attackers who have gained access to mysql system user to further escalate their privileges to root user allowing them to fully compromise the system.

Users should upgrade to their relevant incremental release.

Percona Server

Percona XtraDB Cluster

Users should update as soon as is practical to ensure protection from these vulnerabilities.

Percona would like to thank Dawid Golunski (https://legalhackers.com) for disclosing this issue.

Powered by WordPress | Theme: Aeros 2.0 by TheBuckmaker.com