4.6

CVE-2008-4098

MySQL before 5.0.67 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL home data directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4097.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Canonical ≫ Ubuntu Linux Version 6.06 SwEdition lts
Canonical ≫ Ubuntu Linux Version 7.10
Canonical ≫ Ubuntu Linux Version 8.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 8.10
Canonical ≫ Ubuntu Linux Version 9.04
Canonical ≫ Ubuntu Linux Version 9.10
Debian ≫ Debian Linux Version 5.0
Mysql ≫ Mysql Version 5.0.0
Mysql ≫ Mysql Version 5.0.1
Mysql ≫ Mysql Version 5.0.2
Mysql ≫ Mysql Version 5.0.3
Mysql ≫ Mysql Version 5.0.4
Mysql ≫ Mysql Version 5.0.5
Mysql ≫ Mysql Version 5.0.10
Mysql ≫ Mysql Version 5.0.15
Mysql ≫ Mysql Version 5.0.16
Mysql ≫ Mysql Version 5.0.17
Mysql ≫ Mysql Version 5.0.20
Mysql ≫ Mysql Version 5.0.24
Mysql ≫ Mysql Version 5.0.30
Mysql ≫ Mysql Version 5.0.36
Mysql ≫ Mysql Version 5.0.44
Mysql ≫ Mysql Version 5.0.54
Mysql ≫ Mysql Version 5.0.56
Mysql ≫ Mysql Version 5.0.60
Mysql ≫ Mysql Version 5.0.66
Oracle ≫ Mysql Version 5.0.23
Oracle ≫ Mysql Version 5.0.25
Oracle ≫ Mysql Version 5.0.26
Oracle ≫ Mysql Version 5.0.28
Oracle ≫ Mysql Version 5.0.30 Update sp1
Oracle ≫ Mysql Version 5.0.32
Oracle ≫ Mysql Version 5.0.34
Oracle ≫ Mysql Version 5.0.36 Update sp1
Oracle ≫ Mysql Version 5.0.38
Oracle ≫ Mysql Version 5.0.40
Oracle ≫ Mysql Version 5.0.41
Oracle ≫ Mysql Version 5.0.42
Oracle ≫ Mysql Version 5.0.44 Update sp1
Oracle ≫ Mysql Version 5.0.45
Oracle ≫ Mysql Version 5.0.46
Oracle ≫ Mysql Version 5.0.48
Oracle ≫ Mysql Version 5.0.50
Oracle ≫ Mysql Version 5.0.50 Update sp1
Oracle ≫ Mysql Version 5.0.51
Oracle ≫ Mysql Version 5.0.52
Oracle ≫ Mysql Version 5.0.56 Update sp1
Oracle ≫ Mysql Version 5.0.58
Oracle ≫ Mysql Version 5.0.60 Update sp1
Oracle ≫ Mysql Version 5.0.62
Oracle ≫ Mysql Version 5.0.64
Oracle ≫ Mysql Version 5.0.66 Update sp1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.62% 0.73
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.6 3.9 6.4
AV:N/AC:H/Au:S/C:P/I:P/A:P
CWE-59 Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.html
Third Party Advisory
http://secunia.com/advisories/32759
Not Applicable
http://www.ubuntu.com/usn/USN-1397-1
http://bugs.mysql.com/bug.php?id=32167
Patch
Vendor Advisory
Issue Tracking
http://secunia.com/advisories/32769
Not Applicable
http://www.ubuntu.com/usn/USN-671-1
Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2009:094
Broken Link
http://www.redhat.com/support/errata/RHSA-2009-1067.html
Third Party Advisory
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=480292#25
Third Party Advisory
Issue Tracking
http://www.openwall.com/lists/oss-security/2008/09/09/20
Third Party Advisory
Mailing List
http://www.openwall.com/lists/oss-security/2008/09/16/3
Third Party Advisory
Mailing List
http://secunia.com/advisories/32578
Not Applicable
http://secunia.com/advisories/38517
Not Applicable
http://ubuntu.com/usn/usn-897-1
Third Party Advisory
http://www.debian.org/security/2008/dsa-1662
Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2010-0110.html
Third Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/45649
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10591