MySQL 0-day could lead to total system compromise
Sep 13, 2016, 10:00 (0 Talkback[s])
(Other stories by Anonymous)
Researcher Dawid Golunski has discovered multiple severe vulnerabilities affecting the popular open source database MySQL and its forks. One of these 'CVE-2016-6662 can be exploited by attackers to inject malicious settings into MySQL configuration files or create new ones, allowing them to execute arbitrary code with root privileges when the MySQL service is restarted. This could lead to total compromise of the server running the vulnerable MySQL version.