CVE-2016-6664

Source
https://cve.org/CVERecord?id=CVE-2016-6664
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-6664.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2016-6664
Downstream
Related
Published
2016-12-13T21:59:01.740Z
Modified
2026-04-16T06:19:33.588472549Z
Severity
  • 7.0 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2, 5.6.x before 5.6.32-78-1, and 5.7.x before 5.7.14-8; and Percona XtraDB Cluster before 5.5.41-37.0, 5.6.x before 5.6.32-25.17, and 5.7.x before 5.7.14-26.17, when using file-based logging, allows local users with access to the mysql account to gain root privileges via a symlink attack on error logs and possibly other files.

References

Affected packages

Git / github.com/mariadb/server

Affected ranges

Type
GIT
Repo
https://github.com/mariadb/server
Events
Database specific
{
    "versions": [
        {
            "introduced": "10.0.0"
        },
        {
            "fixed": "10.0.29"
        },
        {
            "introduced": "10.1.0"
        },
        {
            "fixed": "10.1.21"
        }
    ]
}
Type
GIT
Repo
https://github.com/mysql/mysql-server
Events
Introduced
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "5.5.0"
        },
        {
            "last_affected": "5.5.51"
        },
        {
            "introduced": "5.6.0"
        },
        {
            "last_affected": "5.6.32"
        },
        {
            "introduced": "5.7.0"
        },
        {
            "last_affected": "5.7.14"
        },
        {
            "introduced": "5.5.0"
        },
        {
            "fixed": "5.5.54"
        }
    ]
}
Type
GIT
Repo
https://github.com/percona/percona-server
Events
Introduced
Fixed
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Introduced
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "5.5"
        },
        {
            "fixed": "5.5.51-38.2"
        },
        {
            "introduced": "5.6"
        },
        {
            "fixed": "5.6.32-78.1"
        },
        {
            "introduced": "5.7"
        },
        {
            "fixed": "5.7.14-8"
        },
        {
            "introduced": "5.5"
        },
        {
            "fixed": "5.5.41-37.0"
        }
    ]
}
Type
GIT
Repo
https://github.com/percona/percona-xtradb-cluster
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "5.6"
        },
        {
            "fixed": "5.6.32-25.17"
        },
        {
            "introduced": "5.7"
        },
        {
            "fixed": "5.7.14-26.17"
        }
    ]
}

Affected versions

Percona-Server-5.*
Percona-Server-5.5.34-32.0
Percona-Server-5.5.35-33.0
Percona-Server-5.5.51-38.1
Percona-Server-5.6.14-62.0
Percona-Server-5.6.15-63.0
Percona-Server-5.6.22-72.0
Percona-Server-5.6.32-78.0
Percona-Server-5.6.5-60.0
Percona-Server-5.7.14-7
Percona-XtraDB-Cluster-5.*
Percona-XtraDB-Cluster-5.6.14-25.1
Percona-XtraDB-Cluster-5.6.15-25.2
Percona-XtraDB-Cluster-5.6.15-25.3
Percona-XtraDB-Cluster-5.6.15-25.4
Percona-XtraDB-Cluster-5.6.15-25.5
Percona-XtraDB-Cluster-5.6.19-25.6
Percona-XtraDB-Cluster-5.6.20-25.7
Percona-XtraDB-Cluster-5.6.24-25.11
clone-5.*
clone-5.1.0-build
clone-5.1.31-pv-0.2.0-build
clone-5.1.4-build
clone-5.4.0-build
clone-5.6.3-m5-build
clone-5.6.3-m6-build
last-PS-5.*
last-PS-5.5-as-patches
mariadb-10.*
mariadb-10.1.0
mariadb-10.1.10
mariadb-10.1.11
mariadb-10.1.12
mariadb-10.1.13
mariadb-10.1.14
mariadb-10.1.15
mariadb-10.1.16
mariadb-10.1.17
mariadb-10.1.18
mariadb-10.1.19
mariadb-10.1.2
mariadb-10.1.20
mariadb-10.1.3
mariadb-10.1.4
mariadb-10.1.5
mariadb-10.1.6
mariadb-10.1.7
mariadb-10.1.8
mariadb-10.1.9
mysql-3.*
mysql-3.23.22-beta
mysql-3.23.28-gamma
mysql-3.23.30-gamma
mysql-3.23.31
mysql-3.23.32
mysql-3.23.33
mysql-3.23.36
mysql-4.*
mysql-4.0.2
mysql-4.0.4
mysql-5.*
mysql-5.1.4
mysql-5.5.15
mysql-5.5.19
mysql-5.5.23
mysql-5.5.25
mysql-5.5.27
mysql-5.5.44
mysql-5.5.47
mysql-5.5.49
mysql-5.5.51
mysql-5.6.32
mysql-5.7.14
mysql_4.*
mysql_4.0
mysqlsummit-0.*
mysqlsummit-0.2.0
mysqlsummit-0.2.0-build
mysqlsummit-0.2.1
mysqlsummit-0.2.1-build
Other
pre-null-merge
pxc_5.*
pxc_5.6.25-25.12-3.12

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-6664.json"
vanir_signatures
[
    {
        "signature_type": "Function",
        "signature_version": "v1",
        "deprecated": false,
        "digest": {
            "length": 1075.0,
            "function_hash": "326577626690167958606778565745841641029"
        },
        "source": "https://github.com/mariadb/server/commit/5fc1ba604e27b7d9eaa2977ef5b0c180f6f62565",
        "target": {
            "function": "wsrep_calc_row_hash",
            "file": "storage/xtradb/handler/ha_innodb.cc"
        },
        "id": "CVE-2016-6664-2235861b"
    },
    {
        "signature_type": "Function",
        "signature_version": "v1",
        "deprecated": false,
        "digest": {
            "length": 4678.0,
            "function_hash": "175766638502419520218478376205151830061"
        },
        "source": "https://github.com/mariadb/server/commit/5fc1ba604e27b7d9eaa2977ef5b0c180f6f62565",
        "target": {
            "function": "wsrep_store_key_val_for_row",
            "file": "storage/xtradb/handler/ha_innodb.cc"
        },
        "id": "CVE-2016-6664-76d7bb16"
    },
    {
        "source": "https://github.com/mariadb/server/commit/5fc1ba604e27b7d9eaa2977ef5b0c180f6f62565",
        "target": {
            "file": "storage/xtradb/handler/ha_innodb.cc"
        },
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "333910009814716899599761924093289489726",
                "161392224999518567510718607174078569010",
                "161097539754424727880941917296259394470",
                "86950865214847603434991963376525204394",
                "149603238303571009756227611135528613560",
                "246754121958178494555659751381354980297",
                "112180117738318881565344278433296106535",
                "56934855970519006216491266214889014278",
                "177233899003535037117533813868483428969",
                "91781135331166554714959393998795539181",
                "231826346572631787101747650932251996807",
                "120129231197026531763378830534168927209",
                "78750874032296690609296176761798461946",
                "37466225183381131843040316628502534513",
                "73966958620296014639090697993023755838",
                "302517151867660583156292446738041253690",
                "320251111942484271165771358375346713457",
                "137617643939518963627606737565894291194"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2016-6664-d7841ca0",
        "signature_type": "Line",
        "signature_version": "v1"
    }
]
vanir_signatures_modified
"2026-04-11T05:00:41Z"