mysqlinstalldb in MariaDB 10.4.7 through 10.4.11 allows privilege escalation from the mysql user account to root because chown and chmod are performed unsafely, as demonstrated by a symlink attack on a chmod 04755 of authpamtooldir/authpamtool. NOTE: this does not affect the Oracle MySQL product, which implements mysqlinstall_db differently.
{ "binaries": [ { "binary_name": "libmysqlclient-dev", "binary_version": "5.5.62-0ubuntu0.14.04.1" }, { "binary_name": "libmysqlclient18", "binary_version": "5.5.62-0ubuntu0.14.04.1" }, { "binary_name": "libmysqld-dev", "binary_version": "5.5.62-0ubuntu0.14.04.1" }, { "binary_name": "libmysqld-pic", "binary_version": "5.5.62-0ubuntu0.14.04.1" }, { "binary_name": "mysql-client", "binary_version": "5.5.62-0ubuntu0.14.04.1" }, { "binary_name": "mysql-client-5.5", "binary_version": "5.5.62-0ubuntu0.14.04.1" }, { "binary_name": "mysql-client-core-5.5", "binary_version": "5.5.62-0ubuntu0.14.04.1" }, { "binary_name": "mysql-common", "binary_version": "5.5.62-0ubuntu0.14.04.1" }, { "binary_name": "mysql-server", "binary_version": "5.5.62-0ubuntu0.14.04.1" }, { "binary_name": "mysql-server-5.5", "binary_version": "5.5.62-0ubuntu0.14.04.1" }, { "binary_name": "mysql-server-core-5.5", "binary_version": "5.5.62-0ubuntu0.14.04.1" }, { "binary_name": "mysql-source-5.5", "binary_version": "5.5.62-0ubuntu0.14.04.1" }, { "binary_name": "mysql-testsuite", "binary_version": "5.5.62-0ubuntu0.14.04.1" }, { "binary_name": "mysql-testsuite-5.5", "binary_version": "5.5.62-0ubuntu0.14.04.1" } ] }
{ "binaries": [ { "binary_name": "libmariadbd-dev", "binary_version": "10.0.38-0ubuntu0.16.04.1" }, { "binary_name": "libmariadbd18", "binary_version": "10.0.38-0ubuntu0.16.04.1" }, { "binary_name": "mariadb-client", "binary_version": "10.0.38-0ubuntu0.16.04.1" }, { "binary_name": "mariadb-client-10.0", "binary_version": "10.0.38-0ubuntu0.16.04.1" }, { "binary_name": "mariadb-client-core-10.0", "binary_version": "10.0.38-0ubuntu0.16.04.1" }, { "binary_name": "mariadb-common", "binary_version": "10.0.38-0ubuntu0.16.04.1" }, { "binary_name": "mariadb-plugin-connect", "binary_version": "10.0.38-0ubuntu0.16.04.1" }, { "binary_name": "mariadb-plugin-mroonga", "binary_version": "10.0.38-0ubuntu0.16.04.1" }, { "binary_name": "mariadb-plugin-oqgraph", "binary_version": "10.0.38-0ubuntu0.16.04.1" }, { "binary_name": "mariadb-plugin-spider", "binary_version": "10.0.38-0ubuntu0.16.04.1" }, { "binary_name": "mariadb-plugin-tokudb", "binary_version": "10.0.38-0ubuntu0.16.04.1" }, { "binary_name": "mariadb-server", "binary_version": "10.0.38-0ubuntu0.16.04.1" }, { "binary_name": "mariadb-server-10.0", "binary_version": "10.0.38-0ubuntu0.16.04.1" }, { "binary_name": "mariadb-server-core-10.0", "binary_version": "10.0.38-0ubuntu0.16.04.1" }, { "binary_name": "mariadb-test", "binary_version": "10.0.38-0ubuntu0.16.04.1" }, { "binary_name": "mariadb-test-data", "binary_version": "10.0.38-0ubuntu0.16.04.1" } ] }