Red Hat released MariaDB updates for Red Hat Enterprise Linux 7 and Red Hat Software Collections that remediate CVE-2016-2047, a TLS/X.509 hostname-validation flaw in the MariaDB client library. A man-in-the-middle attacker could exploit the defect to impersonate a database server during encrypted connections. The updates include MariaDB 5.5.47 for RHEL 7, 5.5.49 for the mariadb55-mariadb Software Collection, and rh-mariadb100-mariadb 10.0.25-4 for supported RHEL 6 and 7 Software Collections systems.
The advisories also address numerous Oracle MySQL-derived defects, including CVE-2015-4792, CVE-2015-4802, CVE-2015-4815, and CVE-2015-4870 in MySQL Server Partition, DDL, and Parser components. Authenticated network attackers could use these flaws against affected MySQL versions to hang or repeatedly crash database servers, causing complete denial of service; the Software Collections MariaDB update additionally fixes PCRE regular-expression issues that could crash MariaDB or potentially allow arbitrary code execution. Red Hat noted that mysqld restarts automatically after installation.

See real exploitation activity before you spend the cycle.
18 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Moderate-severity RHSA-2016:1481 for mariadb55-mariadb in Software Collections, upgrading it to version 5.5.49. The update remediated CVE-2016-2047 and 38 additional MariaDB/MySQL vulnerabilities from Oracle Critical Patch Updates, including the October 2015 partition, DDL, and parser flaws.
Red Hat issued Important-severity RHSA-2016:1132 for RHEL 6 and 7 Software Collections, providing rh-mariadb100-mariadb 10.0.25-4. It fixed CVE-2016-2047, the October 2015 MySQL flaws, additional MySQL/MariaDB issues, and PCRE vulnerabilities that could crash MariaDB or potentially permit arbitrary code execution through crafted SQL regular expressions.
Red Hat fixed CVE-2016-0611 in rh-mysql56-mysql packages for Red Hat Software Collections on RHEL 6 and 7 through RHSA-2016:0705. The moderate-severity authenticated remote Optimizer flaw could partially affect MySQL service availability.
Red Hat remediated CVE-2016-0665 through RHSA-2016:0705 for affected Red Hat Software Collections releases on RHEL 6 and 7. The MySQL Server Security: Encryption flaw affected MySQL 5.6.28 and earlier and 5.7.10 and earlier and could allow a low-privileged authenticated attacker to repeatedly hang or crash the server.
Red Hat issued RHSA-2016:0705 for RHEL 6 and 7 Software Collections, fixing CVE-2016-0610 in rh-mysql56-mysql. The flaw allowed remote authenticated users to affect availability through unspecified InnoDB-related vectors.
Oracle documented CVE-2016-0655 in its April 2016 Critical Patch Update. The difficult-to-exploit InnoDB flaw affected MySQL 5.6.29 and earlier and 5.7.11 and earlier; a low-privileged authenticated attacker could cause repeated hangs or crashes resulting in complete denial of service.
Red Hat issued Moderate-severity RHSA-2016:0534 for RHEL 7, upgrading MariaDB to 5.5.47. The update remediated the four October 2015 MySQL flaws and CVE-2016-2047, which could enable TLS man-in-the-middle server impersonation, along with other vulnerabilities and an InnoDB AUTO_INCREMENT race condition.
Martin Prpič documented CVE-2016-0605 in the MySQL Server: General component, and Oracle referenced it in its January 2016 Critical Patch Update. An authenticated network attacker could cause MySQL Server 5.6.26 and earlier to hang or repeatedly crash, resulting in complete denial of service; Red Hat later addressed it through RHSA-2016:0705.
Martin Prpič recorded CVE-2016-0503, an easily exploitable MySQL Server: DML vulnerability affecting MySQL 5.6.27 and earlier and 5.7.9. An authenticated remote attacker could cause repeated server hangs or crashes resulting in complete denial of service; Red Hat addressed it in Software Collections through RHSA-2016:0705.
Martin Prpič documented CVE-2016-0504 in the MySQL Server Server: DML component. Authenticated remote attackers could exploit affected MySQL 5.6.27 and earlier and 5.7.9 systems to cause an operating-system hang or repeatable complete denial-of-service crash; Red Hat later addressed it through RHSA-2016:0705.
Martin Prpič documented CVE-2016-0611 in the MySQL Server Optimizer component. Authenticated network attackers could cause MySQL 5.6.27 and earlier or 5.7.9 to hang or repeatedly crash, resulting in complete denial of service; Red Hat later addressed it through RHSA-2016:0705.
Oracle referenced CVE-2016-0595 in its January 2016 Critical Patch Update. The easily exploitable authenticated remote MySQL Server: DML flaw affected MySQL 5.6.27 and earlier and could cause repeatable hangs or crashes resulting in complete denial of service; Red Hat remediated it through RHSA-2016:0705.
CVE-2016-0607 affected the MySQL Server Replication component in MySQL 5.6.27 and earlier and 5.7.9. A difficult-to-exploit, remotely reachable attacker with multiple authentications could cause the server to hang or repeatedly crash, resulting in complete denial of service; Red Hat addressed it through RHSA-2016:0705.
MariaDB fixed the 15-year-old SSL server-certificate hostname-validation flaw CVE-2016-2047 in versions 5.5.47, 10.0.23, and 10.1.10. The issue also affected MySQL and Percona Server clients and could permit man-in-the-middle attacks by accepting a certificate issued for a different host.
Oracle's October 2015 CPU documented CVE-2015-4816, affecting the InnoDB component of MySQL Server 5.5.44 and earlier. An authenticated network attacker could use multiple protocols to hang or repeatedly crash the server, causing denial of service; MariaDB addressed it in version 10.0.21.
Oracle's October 2015 Critical Patch Update documented CVE-2015-4792 and CVE-2015-4802 in Server: Partition, CVE-2015-4815 in Server: DDL, and CVE-2015-4870 in Server: Parser. Affected MySQL versions could be made to hang or repeatedly crash, causing denial of service, by authenticated network attackers.
Red Hat released RHSA-2015:1628 for RHEL 5 mysql55-mysql and RHSA-2015:1629 for RHEL 6 Software Collections mysql55-mysql, remediating the InnoDB availability flaw CVE-2015-4816.
MariaDB addressed CVE-2015-4792, CVE-2015-4802, CVE-2015-4815, and CVE-2015-4870 in MariaDB 10.0.22.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
28 references tracked. Mallory keeps watching after this page renders.
rhn.redhat.com
Open sourceaccess.redhat.com
Open sourcerhn.redhat.com
Open sourcerhn.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceopenwall.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.