6.1 Suspicious UDFs

Information

This will help prevent an attacker from executing arbitrary code. This option prevents attaching arbitrary shared library functions as user-defined functions by checking for at least one corresponding method named _init, _deinit, _reset, _clear, or _add.

Solution

Avoid using the --allow-suspicious-udfs parameter

See Also

https://benchmarks.cisecurity.org/tools2/mysql/CIS_Oracle_MySQL_Community_Server_5.6_Benchmark_v1.0.0.pdf

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7

Plugin: Unix

Control ID: 6dbb2888da4c87f1a793f681fa8d32462ff3ed8d8361dc88f387116e54bb208d