PT-2009-2714 · Oracle · Mysql Server

Jan Lieskovsky

·

Publicado

2009-11-30

·

Atualizado

2024-06-15

·

CVE-2008-7247

CVSS v2.0

6.0

Média

VetorAV:N/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MySQL versions 5.0.x through 5.0.88 MySQL versions 5.1.x through 5.1.41 MySQL version 6.0 before 6.0.9-alpha
Description The issue allows remote authenticated users to bypass intended access restrictions. This occurs when the data home directory contains a symlink to a different filesystem, and the user calls CREATE TABLE with a DATA DIRECTORY or INDEX DIRECTORY argument referring to a subdirectory that requires following this symlink.
Recommendations For MySQL versions 5.0.x through 5.0.88, update to a version after 5.0.88 to resolve the issue. For MySQL versions 5.1.x through 5.1.41, update to a version after 5.1.41 to resolve the issue. For MySQL version 6.0 before 6.0.9-alpha, update to version 6.0.9-alpha or later to resolve the issue.

Exploit

Correção

Link Following

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-7247
OPENSUSE-SU-2024:10153-1
SUSE-RU-2023:3956-1
SUSE-RU-2023:4991-1

Produtos afetados

Mysql Server