CVE-2017-15945: MariaDB

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

The installation scripts in the Gentoo dev-db/mysql, dev-db/mariadb, dev-db/percona-server, dev-db/mysql-cluster, and dev-db/mariadb-galera packages before 2017-09-29 have chown calls for user-writable directory trees, which allows local users to gain privileges by leveraging access to the mysql account for creation of a link.

Affected products

  • MariaDB MariaDB: before 10.0.30 (fixed in 10.0.30)
  • MySQL MySQL: before 5.6.36 (fixed in 5.6.36)

Published 2017-10-27. Last modified 2026-06-17.