CVE-2017-15365

NameCVE-2017-15365
Descriptionsql/event_data_objects.cc in MariaDB before 10.1.30 and 10.2.x before 10.2.10 and Percona XtraDB Cluster before 5.6.37-26.21-3 and 5.7.x before 5.7.19-29.22-3 allows remote authenticated users with SQL access to bypass intended access restrictions and replicate data definition language (DDL) statements to cluster nodes by leveraging incorrect ordering of DDL replication and ACL checking.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium (attack range: remote)
Debian Bugs884065, 885345

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
mariadb-10.0 (PTS)jessie10.0.32-0+deb8u1undetermined
jessie (security)10.0.35-0+deb8u1undetermined
mariadb-10.1 (PTS)stretch (security), stretch10.1.26-0+deb9u1vulnerable
buster, sid1:10.1.29-6vulnerable
mysql-5.5 (PTS)jessie (security), jessie5.5.60-0+deb8u1fixed
mysql-5.7 (PTS)sid5.7.22-1undetermined
percona-xtrabackup (PTS)jessie, sid2.2.3-2.1undetermined

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
mariadb-10.0source(unstable)undeterminedmedium
mariadb-10.1source(unstable)(unfixed)medium885345
mariadb-10.2source(unstable)(unfixed)medium884065
mysql-5.5source(unstable)(not affected)
mysql-5.7source(unstable)undeterminedmedium
percona-xtrabackupsource(unstable)undeterminedmedium

Notes

[stretch] - mariadb-10.1 <postponed> (Minor issue)
- mysql-5.5 <not-affected> (Vulnerable code not present)
MariaDB: Fixed in 10.2.10, 10.1.30
https://bugzilla.redhat.com/show_bug.cgi?id=1524234
https://www.percona.com/doc/percona-xtradb-cluster/LATEST/release-notes/Percona-XtraDB-Cluster-5.7.19-29.22-3.html
Likely (unconfirmed) fix: https://github.com/MariaDB/server/commit/0b5a5258abbeaf8a0c3a18c7e753699787fdf46e?diff=unified
Possibly only introduced with https://github.com/MariaDB/server/commit/df4dd593f29aec8e2116aec1775ad4b8833d8c93 (mariadb-10.1.1)
starting to be present in mariadb-10.1.1.

Search for package or bug name: Reporting problems