1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

MySQL zero-day exploit puts some servers at risk of hacking

Discussion in 'CSO' started by RSS, Sep 12, 2016.

  1. RSS

    RSS New Member Member

    A publicly disclosed vulnerability in the MySQL database could allow attackers to completely compromise some servers.

    The vulnerability affects "all MySQL servers in default configuration in all version branches (5.7, 5.6, and 5.5) including the latest versions," as well as the MySQL-derived databases MariaDB and Percona DB, according to Dawid Golunski, the researcher who found it.

    The flaw, tracked as CVE-2016-6662, can be exploited to modify the MySQL configuration file (my.cnf) and cause an attacker-controlled library to be executed with root privileges if the MySQL process is started with the mysqld_safe wrapper script.

    The exploit can be executed if the attacker has an authenticated connection to the MySQL service, which is common in shared hosting environments, or through an SQL injection flaw, a common type of vulnerability in websites.

    To read this article in full or to leave a comment, please click here

    Continue reading...
     

Share This Page