Where the open source database community meets: Use code PERCONA75 and secure your spot for Percona Live.  Register

Percona Server Critical Update CVE-2016-6662

September 12, 2016
Author
David Busby
Share this Post:

CVE-2016-6662This blog is an announcement for a Percona Server update with regards to CVE-2016-6662.

We have added a fix for CVE-2016-6662 in the following releases:

From seclist.org:

An independent research has revealed multiple severe MySQL vulnerabilities. This advisory focuses on a critical vulnerability with a CVEID of CVE-2016-6662. The vulnerability affects MySQL servers in all version branches (5.7, 5.6, and 5.5) including the latest versions, and could be exploited by both local and remote attackers.

Both the authenticated access to MySQL database (via network connection or web interfaces such as phpMyAdmin) and SQL Injection could be used as exploitation vectors. Successful exploitation could allow attackers to execute arbitrary code with root privileges which would then allow them to fully compromise the server on which an affected version of MySQL is running.

This is a CRITICAL update, and the fix mitigates the potential for remote root code execution.

We encourage our users to update to the latest version of their particular fork as soon as possible, ensuring they have appropriate change management procedures in place beforehand so they can test the update before placing it into production.

Percona would like to thank Dawid Golunski of http://legalhackers.com/ for disclosing this vulnerability in the MySQL software, and working with us to resolve this problem.

0 0 votes
Article Rating
Subscribe
Notify of
guest

17 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
scaarup
scaarup
9 years ago

What about the Percona-XtraDB-Cluster package?

Mark Maas
9 years ago
Reply to  scaarup

Ah So I’m not the only one. I thought I had caching issues somewhere or something. But it seems XtraDB has not been patched yet.

Remco
Remco
9 years ago

Just curious if Percona XtraDB Cluster is also affected… And when to expect patches, if yes.

keshav
keshav
9 years ago

‘@Remco
As confirmed by percona in mail to users, For that release will come next week.

anu
anu
9 years ago

What about those who were already on percona 5.7.14 7 before this Announcement .Was earlier Binary already patched or need to re download latest binaries.

Mike Waddle
Mike Waddle
9 years ago

We ran into memory issues after going from 5.6.23 to this patch. Suspect a memory leak.

scaarup
scaarup
9 years ago
Reply to  Mike Waddle

How did you identify this? Is this potential bug tracked elsewhere?

David Holoboff
David Holoboff
9 years ago
Reply to  Mike Waddle

It appears that we ran into a memory leak as well.

kastauyra
kastauyra
9 years ago

Anyone affected by this memory leak – are you using the audit log plugin?

ram
ram
9 years ago

Anybody is using the audit log plugin?

Yusuf
Yusuf
7 years ago

The link for “Percona Server 5.6.32-78.1” is not correct!

Far
Enough.

Said no pioneer ever.
MySQL, PostgreSQL, InnoDB, MariaDB, MongoDB and Kubernetes are trademarks for their respective owners.
© 2026 Percona All Rights Reserved