Polish security researcher Dawid Golunski has discovered two zero-day vulnerabilities (CVE-2016-6662 and CVE-2016-6663), which operate in all currently supported versions of MySQL. The vulnerabilities allow an attacker to take complete control of any database.
Golunski says he has notified Oracle of the two vulnerabilities, as well as all developers of the MySQL forks, MariaDB and PerconaDB.
Today, the researcher, after seeing that only the developers of MariaDB and PerconaDB identified the vulnerabilities while the directly concerned company Oracle did not pay attention, published the PoC of the vulnerability.

It should be noted that Oracle is committed to a strict schedule for security updates that are released every three months. The last critical update released by Oracle (Critical Patch Update or CPU) was released on July 19.
Golunski reported the vulnerabilities to Oracle on July 29th, and according to the researcher, Oracle's security team acknowledged the vulnerabilities. However, the next Oracle CPU is scheduled for October 18th, 2016.
“The vulnerabilities have been patched by PerconaDB and MariaDB developers as of August 30th,” Golunski says.
“During the patching process, developers also reported on public logs the ongoing security issues.”
"However, it has been over 40 days since the issues were reported and I decided to disclose (with a limited PoC) the vulnerabilities to inform users of the risks before the next CPU update arrives at the end of October," the researcher says.
The vulnerabilities now:
CVE-2016-6662 allows an attacker, from a remote or local location, to inject custom settings into the my.conf configuration file of any MySQL database.
The issue only affects MySQL servers running the default config, and is triggered after the first database restart to read the new settings from my.conf. Database servers often reboot during system updates, and package updates.
CVE-2016-6662 now allows attackers to modify the my.conf file, load third-party code, and run it with root privileges.
Golunski also reports the vulnerability CVE-2016-6663, which is a variant of CVE-2016-6662. This particular vulnerability allows remote code execution as root.
The researcher has suggested some temporary solutions to protect servers until Oracle fixes the vulnerabilities in its next CPU.
“A temporary solution is to ensure that there are no MySQL configuration files owned (permissions) by the MySQL user, and create dummy my.cnf files with root permissions that are not used.”
Golunski says that the above is only a temporary solution and that patches should be applied as soon as they are released.
