PT-2003-1400 · Mysql Server · Mysql Server

Gufino

·

Publicado

2003-03-21

·

Atualizado

2019-10-07

·

CVE-2003-0150

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: MySQL versions 3.23.55 and earlier
Description: The issue allows mysql users to gain root privileges by creating world-writeable files and overwriting a configuration file using the "SELECT * INFO OUTFILE" operator. This can cause mysql to run as root upon restart, as demonstrated by modifying the my.cnf configuration file.
Recommendations: For MySQL versions 3.23.55 and earlier, consider restricting access to the SELECT * INFO OUTFILE operator until a fix is available. As a temporary workaround, restrict write access to configuration files, such as my.cnf, to prevent unauthorized modifications.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2003-0150

Produtos afetados

Mysql Server