CVE-2015-5969
published 2016-04-08CVE-2015-5969: The mysql-systemd-helper script in the mysql-community-server package before 5.6.28-2.17.1 in openSUSE 13.2 and before 5.6.28-13.1 in openSUSE Leap 42.1 and…
PriorityP425medium6.2CVSS 3.0
AVLACLPRNUINSUCHINAN
EPSS
0.39%
31.6th percentile
The mysql-systemd-helper script in the mysql-community-server package before 5.6.28-2.17.1 in openSUSE 13.2 and before 5.6.28-13.1 in openSUSE Leap 42.1 and the mariadb package before 10.0.22-2.21.2 in openSUSE 13.2 and before 10.0.22-3.1 in SUSE Linux Enterprise (SLE) 12.1 and openSUSE Leap 42.1 allows local users to discover database credentials by listing a process and its arguments.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_software_development_kit | — | — |
| suse | linux_enterprise_workstation_extension | — | — |
CVSS provenance
nvdv3.06.2MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00015.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00039.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00050.htmlhttps://bugzilla.suse.com/957174https://www.suse.com/support/update/announcement/2016/suse-su-20160296-1.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00015.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00039.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00050.htmlhttps://bugzilla.suse.com/957174https://www.suse.com/support/update/announcement/2016/suse-su-20160296-1.html
2016-04-08
Published