Vulnerability Details CVE-2016-6664
mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2, 5.6.x before 5.6.32-78-1, and 5.7.x before 5.7.14-8; and Percona XtraDB Cluster before 5.5.41-37.0, 5.6.x before 5.6.32-25.17, and 5.7.x before 5.7.14-26.17, when using file-based logging, allows local users with access to the mysql account to gain root privileges via a symlink attack on error logs and possibly other files.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.498
EPSS Ranking 97.6%
CVSS Severity
CVSS v3 Score 7.0
CVSS v2 Score 6.9
Products affected by CVE-2016-6664
-
cpe:2.3:a:mariadb:mariadb:10.0.0
-
cpe:2.3:a:mariadb:mariadb:10.0.1
-
cpe:2.3:a:mariadb:mariadb:10.0.10
-
cpe:2.3:a:mariadb:mariadb:10.0.11
-
cpe:2.3:a:mariadb:mariadb:10.0.12
-
cpe:2.3:a:mariadb:mariadb:10.0.13
-
cpe:2.3:a:mariadb:mariadb:10.0.14
-
cpe:2.3:a:mariadb:mariadb:10.0.15
-
cpe:2.3:a:mariadb:mariadb:10.0.16
-
cpe:2.3:a:mariadb:mariadb:10.0.17
-
cpe:2.3:a:mariadb:mariadb:10.0.18
-
cpe:2.3:a:mariadb:mariadb:10.0.19
-
cpe:2.3:a:mariadb:mariadb:10.0.2
-
cpe:2.3:a:mariadb:mariadb:10.0.20
-
cpe:2.3:a:mariadb:mariadb:10.0.21
-
cpe:2.3:a:mariadb:mariadb:10.0.22
-
cpe:2.3:a:mariadb:mariadb:10.0.23
-
cpe:2.3:a:mariadb:mariadb:10.0.24
-
cpe:2.3:a:mariadb:mariadb:10.0.25
-
cpe:2.3:a:mariadb:mariadb:10.0.26
-
cpe:2.3:a:mariadb:mariadb:10.0.27
-
cpe:2.3:a:mariadb:mariadb:10.0.28
-
cpe:2.3:a:mariadb:mariadb:10.0.3
-
cpe:2.3:a:mariadb:mariadb:10.0.4
-
cpe:2.3:a:mariadb:mariadb:10.0.5
-
cpe:2.3:a:mariadb:mariadb:10.0.6
-
cpe:2.3:a:mariadb:mariadb:10.0.7
-
cpe:2.3:a:mariadb:mariadb:10.0.8
-
cpe:2.3:a:mariadb:mariadb:10.0.9
-
cpe:2.3:a:mariadb:mariadb:10.1.0
-
cpe:2.3:a:mariadb:mariadb:10.1.1
-
cpe:2.3:a:mariadb:mariadb:10.1.10
-
cpe:2.3:a:mariadb:mariadb:10.1.11
-
cpe:2.3:a:mariadb:mariadb:10.1.12
-
cpe:2.3:a:mariadb:mariadb:10.1.13
-
cpe:2.3:a:mariadb:mariadb:10.1.14
-
cpe:2.3:a:mariadb:mariadb:10.1.15
-
cpe:2.3:a:mariadb:mariadb:10.1.16
-
cpe:2.3:a:mariadb:mariadb:10.1.17
-
cpe:2.3:a:mariadb:mariadb:10.1.18
-
cpe:2.3:a:mariadb:mariadb:10.1.19
-
cpe:2.3:a:mariadb:mariadb:10.1.2
-
cpe:2.3:a:mariadb:mariadb:10.1.20
-
cpe:2.3:a:mariadb:mariadb:10.1.3
-
cpe:2.3:a:mariadb:mariadb:10.1.4
-
cpe:2.3:a:mariadb:mariadb:10.1.5
-
cpe:2.3:a:mariadb:mariadb:10.1.6
-
cpe:2.3:a:mariadb:mariadb:10.1.7
-
cpe:2.3:a:mariadb:mariadb:10.1.8
-
cpe:2.3:a:mariadb:mariadb:10.1.9
-
cpe:2.3:a:mariadb:mariadb:5.5.0
-
cpe:2.3:a:mariadb:mariadb:5.5.20
-
cpe:2.3:a:mariadb:mariadb:5.5.21
-
cpe:2.3:a:mariadb:mariadb:5.5.22
-
cpe:2.3:a:mariadb:mariadb:5.5.23
-
cpe:2.3:a:mariadb:mariadb:5.5.24
-
cpe:2.3:a:mariadb:mariadb:5.5.25
-
cpe:2.3:a:mariadb:mariadb:5.5.27
-
cpe:2.3:a:mariadb:mariadb:5.5.28
-
cpe:2.3:a:mariadb:mariadb:5.5.28a
-
cpe:2.3:a:mariadb:mariadb:5.5.33
-
cpe:2.3:a:mariadb:mariadb:5.5.34
-
cpe:2.3:a:mariadb:mariadb:5.5.35
-
cpe:2.3:a:mariadb:mariadb:5.5.40
-
cpe:2.3:a:mariadb:mariadb:5.5.43
-
cpe:2.3:a:mariadb:mariadb:5.5.46
-
cpe:2.3:a:mariadb:mariadb:5.5.47
-
cpe:2.3:a:mariadb:mariadb:5.5.48
-
cpe:2.3:a:mariadb:mariadb:5.5.49
-
cpe:2.3:a:mariadb:mariadb:5.5.50
-
cpe:2.3:a:mariadb:mariadb:5.5.51
-
cpe:2.3:a:oracle:mysql:5.5.0
-
cpe:2.3:a:oracle:mysql:5.5.1
-
cpe:2.3:a:oracle:mysql:5.5.10
-
cpe:2.3:a:oracle:mysql:5.5.11
-
cpe:2.3:a:oracle:mysql:5.5.12
-
cpe:2.3:a:oracle:mysql:5.5.13
-
cpe:2.3:a:oracle:mysql:5.5.14
-
cpe:2.3:a:oracle:mysql:5.5.15
-
cpe:2.3:a:oracle:mysql:5.5.16
-
cpe:2.3:a:oracle:mysql:5.5.17
-
cpe:2.3:a:oracle:mysql:5.5.18
-
cpe:2.3:a:oracle:mysql:5.5.19
-
cpe:2.3:a:oracle:mysql:5.5.2
-
cpe:2.3:a:oracle:mysql:5.5.20
-
cpe:2.3:a:oracle:mysql:5.5.21
-
cpe:2.3:a:oracle:mysql:5.5.22
-
cpe:2.3:a:oracle:mysql:5.5.23
-
cpe:2.3:a:oracle:mysql:5.5.24
-
cpe:2.3:a:oracle:mysql:5.5.25
-
cpe:2.3:a:oracle:mysql:5.5.26
-
cpe:2.3:a:oracle:mysql:5.5.27
-
cpe:2.3:a:oracle:mysql:5.5.28
-
cpe:2.3:a:oracle:mysql:5.5.29
-
cpe:2.3:a:oracle:mysql:5.5.3
-
cpe:2.3:a:oracle:mysql:5.5.30
-
cpe:2.3:a:oracle:mysql:5.5.31
-
cpe:2.3:a:oracle:mysql:5.5.32
-
cpe:2.3:a:oracle:mysql:5.5.33
-
cpe:2.3:a:oracle:mysql:5.5.34
-
cpe:2.3:a:oracle:mysql:5.5.35
-
cpe:2.3:a:oracle:mysql:5.5.36
-
cpe:2.3:a:oracle:mysql:5.5.37
-
cpe:2.3:a:oracle:mysql:5.5.38
-
cpe:2.3:a:oracle:mysql:5.5.39
-
cpe:2.3:a:oracle:mysql:5.5.4
-
cpe:2.3:a:oracle:mysql:5.5.40
-
cpe:2.3:a:oracle:mysql:5.5.41
-
cpe:2.3:a:oracle:mysql:5.5.42
-
cpe:2.3:a:oracle:mysql:5.5.43
-
cpe:2.3:a:oracle:mysql:5.5.44
-
cpe:2.3:a:oracle:mysql:5.5.45
-
cpe:2.3:a:oracle:mysql:5.5.46
-
cpe:2.3:a:oracle:mysql:5.5.47
-
cpe:2.3:a:oracle:mysql:5.5.48
-
cpe:2.3:a:oracle:mysql:5.5.49
-
cpe:2.3:a:oracle:mysql:5.5.5
-
cpe:2.3:a:oracle:mysql:5.5.50
-
cpe:2.3:a:oracle:mysql:5.5.51
-
cpe:2.3:a:oracle:mysql:5.5.6
-
cpe:2.3:a:oracle:mysql:5.5.7
-
cpe:2.3:a:oracle:mysql:5.5.8
-
cpe:2.3:a:oracle:mysql:5.5.9
-
cpe:2.3:a:oracle:mysql:5.6.0
-
cpe:2.3:a:oracle:mysql:5.6.1
-
cpe:2.3:a:oracle:mysql:5.6.10
-
cpe:2.3:a:oracle:mysql:5.6.11
-
cpe:2.3:a:oracle:mysql:5.6.12
-
cpe:2.3:a:oracle:mysql:5.6.13
-
cpe:2.3:a:oracle:mysql:5.6.14
-
cpe:2.3:a:oracle:mysql:5.6.15
-
cpe:2.3:a:oracle:mysql:5.6.16
-
cpe:2.3:a:oracle:mysql:5.6.17
-
cpe:2.3:a:oracle:mysql:5.6.18
-
cpe:2.3:a:oracle:mysql:5.6.19
-
cpe:2.3:a:oracle:mysql:5.6.2
-
cpe:2.3:a:oracle:mysql:5.6.20
-
cpe:2.3:a:oracle:mysql:5.6.21
-
cpe:2.3:a:oracle:mysql:5.6.22
-
cpe:2.3:a:oracle:mysql:5.6.23
-
cpe:2.3:a:oracle:mysql:5.6.24
-
cpe:2.3:a:oracle:mysql:5.6.25
-
cpe:2.3:a:oracle:mysql:5.6.26
-
cpe:2.3:a:oracle:mysql:5.6.27
-
cpe:2.3:a:oracle:mysql:5.6.28
-
cpe:2.3:a:oracle:mysql:5.6.29
-
cpe:2.3:a:oracle:mysql:5.6.3
-
cpe:2.3:a:oracle:mysql:5.6.30
-
cpe:2.3:a:oracle:mysql:5.6.31
-
cpe:2.3:a:oracle:mysql:5.6.32
-
cpe:2.3:a:oracle:mysql:5.6.4
-
cpe:2.3:a:oracle:mysql:5.6.5
-
cpe:2.3:a:oracle:mysql:5.6.6
-
cpe:2.3:a:oracle:mysql:5.6.7
-
cpe:2.3:a:oracle:mysql:5.6.8
-
cpe:2.3:a:oracle:mysql:5.6.9
-
cpe:2.3:a:oracle:mysql:5.7.0
-
cpe:2.3:a:oracle:mysql:5.7.1
-
cpe:2.3:a:oracle:mysql:5.7.10
-
cpe:2.3:a:oracle:mysql:5.7.11
-
cpe:2.3:a:oracle:mysql:5.7.12
-
cpe:2.3:a:oracle:mysql:5.7.13
-
cpe:2.3:a:oracle:mysql:5.7.14
-
cpe:2.3:a:oracle:mysql:5.7.2
-
cpe:2.3:a:oracle:mysql:5.7.3
-
cpe:2.3:a:oracle:mysql:5.7.4
-
cpe:2.3:a:oracle:mysql:5.7.5
-
cpe:2.3:a:oracle:mysql:5.7.6
-
cpe:2.3:a:oracle:mysql:5.7.7
-
cpe:2.3:a:oracle:mysql:5.7.8
-
cpe:2.3:a:oracle:mysql:5.7.9
-
cpe:2.3:a:percona:percona_server:5.5
-
cpe:2.3:a:percona:percona_server:5.5.10-20.1
-
cpe:2.3:a:percona:percona_server:5.5.11-20.2
-
cpe:2.3:a:percona:percona_server:5.5.12-20.3
-
cpe:2.3:a:percona:percona_server:5.5.13-20.4
-
cpe:2.3:a:percona:percona_server:5.5.14-20.5
-
cpe:2.3:a:percona:percona_server:5.5.15-21.0
-
cpe:2.3:a:percona:percona_server:5.5.16-22.0
-
cpe:2.3:a:percona:percona_server:5.5.18-23.0
-
cpe:2.3:a:percona:percona_server:5.5.19-24.0
-
cpe:2.3:a:percona:percona_server:5.5.20-24.1
-
cpe:2.3:a:percona:percona_server:5.5.21-25.0
-
cpe:2.3:a:percona:percona_server:5.5.21-25.1
-
cpe:2.3:a:percona:percona_server:5.5.22-25.2
-
cpe:2.3:a:percona:percona_server:5.5.23-25.3
-
cpe:2.3:a:percona:percona_server:5.5.24-26.0
-
cpe:2.3:a:percona:percona_server:5.5.25a-27.1
-
cpe:2.3:a:percona:percona_server:5.5.27-28.0
-
cpe:2.3:a:percona:percona_server:5.5.27-28.1
-
cpe:2.3:a:percona:percona_server:5.5.27-29.0
-
cpe:2.3:a:percona:percona_server:5.5.28-29.1
-
cpe:2.3:a:percona:percona_server:5.5.28-29.2
-
cpe:2.3:a:percona:percona_server:5.5.28-29.3
-
cpe:2.3:a:percona:percona_server:5.5.28-29.4
-
cpe:2.3:a:percona:percona_server:5.5.29-30.0
-
cpe:2.3:a:percona:percona_server:5.5.30-30.1
-
cpe:2.3:a:percona:percona_server:5.5.30-30.2
-
cpe:2.3:a:percona:percona_server:5.5.31-30.3
-
cpe:2.3:a:percona:percona_server:5.5.32-31.0
-
cpe:2.3:a:percona:percona_server:5.5.33-31.1
-
cpe:2.3:a:percona:percona_server:5.5.34-32.0
-
cpe:2.3:a:percona:percona_server:5.5.35-33.0
-
cpe:2.3:a:percona:percona_server:5.5.36-34.0
-
cpe:2.3:a:percona:percona_server:5.5.36-34.1
-
cpe:2.3:a:percona:percona_server:5.5.36-34.2
-
cpe:2.3:a:percona:percona_server:5.5.37-35.0
-
cpe:2.3:a:percona:percona_server:5.5.37-35.1
-
cpe:2.3:a:percona:percona_server:5.5.38-35.2
-
cpe:2.3:a:percona:percona_server:5.5.39-36.0
-
cpe:2.3:a:percona:percona_server:5.5.40-36.1
-
cpe:2.3:a:percona:percona_server:5.5.41-37.0
-
cpe:2.3:a:percona:percona_server:5.5.42-37.1
-
cpe:2.3:a:percona:percona_server:5.5.43-37.2
-
cpe:2.3:a:percona:percona_server:5.5.44-37.3
-
cpe:2.3:a:percona:percona_server:5.5.45-37.4
-
cpe:2.3:a:percona:percona_server:5.5.46-37.5
-
cpe:2.3:a:percona:percona_server:5.5.46-37.6
-
cpe:2.3:a:percona:percona_server:5.5.47-37.7
-
cpe:2.3:a:percona:percona_server:5.5.48-37.8
-
cpe:2.3:a:percona:percona_server:5.5.49-37.9
-
cpe:2.3:a:percona:percona_server:5.5.50-38.0
-
cpe:2.3:a:percona:percona_server:5.5.51-38.1
-
cpe:2.3:a:percona:percona_server:5.5.7
-
cpe:2.3:a:percona:percona_server:5.5.8-20
-
cpe:2.3:a:percona:percona_server:5.5.9-20.1
-
cpe:2.3:a:percona:percona_server:5.6
-
cpe:2.3:a:percona:percona_server:5.6.10-60.2
-
cpe:2.3:a:percona:percona_server:5.6.11-60.3
-
cpe:2.3:a:percona:percona_server:5.6.12-60.4
-
cpe:2.3:a:percona:percona_server:5.6.13-60.5
-
cpe:2.3:a:percona:percona_server:5.6.13-60.6
-
cpe:2.3:a:percona:percona_server:5.6.13-61.0
-
cpe:2.3:a:percona:percona_server:5.6.14-62.0
-
cpe:2.3:a:percona:percona_server:5.6.15-63.0
-
cpe:2.3:a:percona:percona_server:5.6.16-64.0
-
cpe:2.3:a:percona:percona_server:5.6.16-64.1
-
cpe:2.3:a:percona:percona_server:5.6.16-64.2
-
cpe:2.3:a:percona:percona_server:5.6.17-65.0
-
cpe:2.3:a:percona:percona_server:5.6.17-66.0
-
cpe:2.3:a:percona:percona_server:5.6.19-67.0
-
cpe:2.3:a:percona:percona_server:5.6.20-68.0
-
cpe:2.3:a:percona:percona_server:5.6.21-69.0
-
cpe:2.3:a:percona:percona_server:5.6.21-70.0
-
cpe:2.3:a:percona:percona_server:5.6.21-70.1
-
cpe:2.3:a:percona:percona_server:5.6.22-71.0
-
cpe:2.3:a:percona:percona_server:5.6.22-72.0
-
cpe:2.3:a:percona:percona_server:5.6.23-72.1
-
cpe:2.3:a:percona:percona_server:5.6.24-72.2
-
cpe:2.3:a:percona:percona_server:5.6.25-73.0
-
cpe:2.3:a:percona:percona_server:5.6.25-73.1
-
cpe:2.3:a:percona:percona_server:5.6.26-74.0
-
cpe:2.3:a:percona:percona_server:5.6.27-75.0
-
cpe:2.3:a:percona:percona_server:5.6.27-76.0
-
cpe:2.3:a:percona:percona_server:5.6.28-76.1
-
cpe:2.3:a:percona:percona_server:5.6.29-76.2
-
cpe:2.3:a:percona:percona_server:5.6.30-76.3
-
cpe:2.3:a:percona:percona_server:5.6.31-77.0
-
cpe:2.3:a:percona:percona_server:5.6.32-78.0
-
cpe:2.3:a:percona:percona_server:5.6.5-60.0
-
cpe:2.3:a:percona:percona_server:5.6.6-60.1
-
cpe:2.3:a:percona:percona_server:5.7
-
cpe:2.3:a:percona:percona_server:5.7.10-1
-
cpe:2.3:a:percona:percona_server:5.7.10-2
-
cpe:2.3:a:percona:percona_server:5.7.10-3
-
cpe:2.3:a:percona:percona_server:5.7.11-4
-
cpe:2.3:a:percona:percona_server:5.7.12-5
-
cpe:2.3:a:percona:percona_server:5.7.13-6
-
cpe:2.3:a:percona:percona_server:5.7.14-7
-
cpe:2.3:a:percona:xtradb_cluster:5.5
-
cpe:2.3:a:percona:xtradb_cluster:5.5.23-23.5
-
cpe:2.3:a:percona:xtradb_cluster:5.5.24-23.6
-
cpe:2.3:a:percona:xtradb_cluster:5.5.27-23.6
-
cpe:2.3:a:percona:xtradb_cluster:5.5.28-23.7
-
cpe:2.3:a:percona:xtradb_cluster:5.5.29-23.7.1
-
cpe:2.3:a:percona:xtradb_cluster:5.5.29-23.7.2
-
cpe:2.3:a:percona:xtradb_cluster:5.5.30-23.7.4
-
cpe:2.3:a:percona:xtradb_cluster:5.5.31-23.7.5
-
cpe:2.3:a:percona:xtradb_cluster:5.5.33-23.7.6
-
cpe:2.3:a:percona:xtradb_cluster:5.5.34-23.7.6
-
cpe:2.3:a:percona:xtradb_cluster:5.5.34-25.9
-
cpe:2.3:a:percona:xtradb_cluster:5.5.37-25.10
-
cpe:2.3:a:percona:xtradb_cluster:5.5.39-25.11
-
cpe:2.3:a:percona:xtradb_cluster:5.5.41-25.11
-
cpe:2.3:a:percona:xtradb_cluster:5.5.41-25.11.1
-
cpe:2.3:a:percona:xtradb_cluster:5.5.41-25.12
-
cpe:2.3:a:percona:xtradb_cluster:5.6
-
cpe:2.3:a:percona:xtradb_cluster:5.6.14-25.1
-
cpe:2.3:a:percona:xtradb_cluster:5.6.15-25.2
-
cpe:2.3:a:percona:xtradb_cluster:5.6.15-25.3
-
cpe:2.3:a:percona:xtradb_cluster:5.6.15-25.4
-
cpe:2.3:a:percona:xtradb_cluster:5.6.15-25.5
-
cpe:2.3:a:percona:xtradb_cluster:5.6.19-25.6
-
cpe:2.3:a:percona:xtradb_cluster:5.6.20-25.7
-
cpe:2.3:a:percona:xtradb_cluster:5.6.21-25.8
-
cpe:2.3:a:percona:xtradb_cluster:5.6.22-25.8
-
cpe:2.3:a:percona:xtradb_cluster:5.6.24-25.11
-
cpe:2.3:a:percona:xtradb_cluster:5.6.25-25.12
-
cpe:2.3:a:percona:xtradb_cluster:5.6.26-25.12
-
cpe:2.3:a:percona:xtradb_cluster:5.6.27-25.13
-
cpe:2.3:a:percona:xtradb_cluster:5.6.28-25.14
-
cpe:2.3:a:percona:xtradb_cluster:5.6.29-25.15
-
cpe:2.3:a:percona:xtradb_cluster:5.6.30-25.16
-
cpe:2.3:a:percona:xtradb_cluster:5.6.30-25.16.2
-
cpe:2.3:a:percona:xtradb_cluster:5.6.30-25.16.3
-
cpe:2.3:a:percona:xtradb_cluster:5.7
-
cpe:2.3:a:percona:xtradb_cluster:5.7.11-25.14.2
-
cpe:2.3:a:percona:xtradb_cluster:5.7.11-4
-
cpe:2.3:a:percona:xtradb_cluster:5.7.12-26.16
-
cpe:2.3:a:percona:xtradb_cluster:5.7.12-5