mariadb: mysql_install_db allows privilege escalation due to unsafe chown and chmod operations
Published Feb 4, 2020
7.8
HIGHCVSS 3.1
EPSS 0.67%
Description
mysql_install_db in MariaDB 10.4.7 through 10.4.11 allows privilege escalation from the mysql user account to root because chown and chmod are performed unsafely, as demonstrated by a symlink attack on a chmod 04755 of auth_pam_tool_dir/auth_pam_tool. NOTE: this does not affect the Oracle MySQL product, which implements mysql_install_db differently.
Affected products
No data.
No data.
Red Hat Enterprise Linux 7
mariadb
Not affected
Red Hat Enterprise Linux 8
mariadb
Not affected
Red Hat OpenStack Platform 13 (Queens)
mariadb
Not affected
Red Hat Software Collections
rh-mariadb102
Not affected
Red Hat Software Collections
rh-mariadb103
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | mariadb | Not affected | n/a |
| Red Hat Enterprise Linux 8 | mariadb | Not affected | n/a |
| Red Hat OpenStack Platform 13 (Queens) | mariadb | Not affected | n/a |
| Red Hat Software Collections | rh-mariadb102 | Not affected | n/a |
| Red Hat Software Collections | rh-mariadb103 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw did not affect the versions of MariaDB as shipped with Red Hat Enterprise Linux 7, and 8 as they did not include the vulnerable code, which was introduced in a newer version of the package. The same is true for the versions of MariaDB as shipped with Red Hat Software Collections 3.
References (8)
- https://access.redhat.com/security/cve/CVE-2020-7221 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1802786 Issue Tracking
- https://bugzilla.suse.com/show_bug.cgi?id=1160868 x_refsource_MISCExploitIssue TrackingThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-28350 Advisory
- https://github.com/MariaDB/server/commit/9d18b6246755472c8324bf3e20e234e08ac45618 x_refsource_CONFIRMThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-7221
- https://seclists.org/oss-sec/2020/q1/55 x_refsource_MISCExploitMailing ListThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-7221
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-7221 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1802786 | Issue Tracking | |
| https://bugzilla.suse.com/show_bug.cgi?id=1160868 | x_refsource_MISCExploitIssue TrackingThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-28350 | Advisory | |
| https://github.com/MariaDB/server/commit/9d18b6246755472c8324bf3e20e234e08ac45618 | x_refsource_CONFIRMThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-7221 | ||
| https://seclists.org/oss-sec/2020/q1/55 | x_refsource_MISCExploitMailing ListThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2020-7221 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data