PT-2013-3572 · Oracle · Mysql Server

Vladz

·

Publicado

2013-08-19

·

Atualizado

2014-01-14

·

CVE-2013-2162

CVSS v2.0

1.9

Baixa

VetorAV:L/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions MySQL Server version 5.5
Description A race condition in the post-installation script for MySQL Server 5.5 creates a configuration file with world-readable permissions before restricting the permissions. This allows local users to read the file and obtain sensitive information, such as credentials.
Recommendations For MySQL Server version 5.5, consider restricting access to the configuration file until the permissions are properly set, or manually adjust the permissions to prevent unauthorized access. As a temporary workaround, restrict read access to the configuration file to minimize the risk of credential exposure.

Exploit

Correção

Race Condition

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-2162
DLA-75-1
DSA-2818-1

Produtos afetados

Mysql Server