PT-2005-3464 · Oracle · Mysql Server

Reid Borsuk

·

Publicado

2005-08-16

·

Atualizado

2019-12-17

·

CVE-2005-2573

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions MySQL versions 4.0 through 4.0.24 MySQL versions 4.1 through 4.1.12 MySQL versions 5.0 through 5.0.6-beta
Description The issue arises from an incomplete blacklist used in a directory traversal check within the mysql create function function. This allows attackers to include arbitrary files using the backslash (``) character when running on Windows.
Recommendations For MySQL versions 4.0 through 4.0.24, update to version 4.0.25 or later. For MySQL versions 4.1 through 4.1.12, update to version 4.1.13 or later. For MySQL versions 5.0 through 5.0.6-beta, update to version 5.0.7-beta or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-2573

Produtos afetados

Mysql Server