Advisories ยป MGASA-2016-0371

Updated mariadb packages fix security vulnerabilities

Publication date: 09 Nov 2016
Modification date: 09 Nov 2016
Type: security
Affected Mageia releases : 5
CVE: CVE-2016-6663 , CVE-2016-3492 , CVE-2016-5584 , CVE-2016-5616 , CVE-2016-5624 , CVE-2016-5626 , CVE-2016-5629 , CVE-2016-7440 , CVE-2016-8283

Description

A race condition was found in the way MariaDB performed MyISAM engine
table repair. A database user with shell access to the server running
mysqld could use this flaw to change permissions of arbitrary files
writable by the mysql system user (CVE-2016-6663).

This update fixes several vulnerabilities in the MariaDB database
server.   Information about these flaws can be found on the Oracle
Critical Patch Update Advisory page, listed in the References section
(CVE-2016-3492, CVE-2016-5584, CVE-2016-5616, CVE-2016-5624,
CVE-2016-5626, CVE-2016-5629, CVE-2016-7440, CVE-2016-8283).
                

References

SRPMS

5/core