← Back to team overview

maria-discuss team mailing list archive

Re: Critical Update for CVE-2016-6662

 

From what i noticed , centos6 hosts that were on mysql 5.6 , or mariadb 10.1.17 is using the mysqld_safe. Upgraded centos7 hosts , and mysqld_safe is no longer a running process for mariadb 10.1.17.

Would this mean that only the hosts that do not run the mysqld_safe are safe ?

On 9/12/2016 9:25 PM, Sergei Golubchik wrote:
Hi, Alex!

On Sep 12, Alex wrote:
Hello,

In regards to this zero day remote exploit , it seems MariaDB is also
affected. Percona seems to have released new versions out to fix this.
Any news from MariaDB side ?

http://legalhackers.com/advisories/MySQL-Exploit-Remote-Root-Code-Execution-Privesc-CVE-2016-6662.html
Yes, it was https://jira.mariadb.org/browse/MDEV-10465,
fixed in 5.5.51, 10.0.27, 10.1.17, all released last month.

Regards,
Sergei
Chief Architect MariaDB
and security@xxxxxxxxxxx



Follow ups

References