PT-1998-1169 · Oracle · Mysql Server
Published
1998-12-27
·
Updated
2019-10-07
·
CVE-1999-1188
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
MySQL version 3.21
Description
The issue allows local users to obtain passwords for users who are added to the user database due to world-readable log file permissions created by mysqld in MySQL.
Recommendations
For MySQL version 3.21, consider changing the log file permissions to prevent world-readable access as a temporary workaround. Restrict access to the log files to minimize the risk of password exposure. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mysql Server