Back

HIGH

mariadb: mysql_install_db allows privilege escalation due to unsafe chown and chmod operations

Published Feb 4, 2020

Description

mysql_install_db in MariaDB 10.4.7 through 10.4.11 allows privilege escalation from the mysql user account to root because chown and chmod are performed unsafely, as demonstrated by a symlink attack on a chmod 04755 of auth_pam_tool_dir/auth_pam_tool. NOTE: this does not affect the Oracle MySQL product, which implements mysql_install_db differently.

Affected products

Remediation

Red Hat statement

This flaw did not affect the versions of MariaDB as shipped with Red Hat Enterprise Linux 7, and 8 as they did not include the vulnerable code, which was introduced in a newer version of the package. The same is true for the versions of MariaDB as shipped with Red Hat Software Collections 3.

Weaknesses (2)

References (8)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published Feb 4, 2020
Updated Aug 4, 2024
Reserved Jan 17, 2020

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Feb 4, 2020
Bugzilla 1802786

ENISA EUVD

Assigner mitre
Published Feb 4, 2020
Updated Aug 4, 2024

GitHub

No data