News

MySQL Workbench also makes it harder to mess up the config file by, say, accidentally inserting a linebreak where it doesn’t belong. Initially, MySQL Workbench doesn’t have an options file ...
The flaw, tracked as CVE-2016-6662, can be exploited to modify the MySQL configuration file (my.cnf) and cause an attacker-controlled library to be executed with root privileges if the MySQL ...
I found that the mysql config file (/etc/mysql/my.cnf) was referencing the user mysql so I changed it to root, and restarted the server.
“As temporary mitigations, users should ensure that no mysql config files are owned by mysql user, and create root-owned dummy my.cnf files that are not in use,” Golunski said in his advisory.