PT-2003-1400 · Mysql Server · Mysql Server

Gufino

·

Published

2003-03-21

·

Updated

2019-10-07

·

CVE-2003-0150

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: MySQL versions 3.23.55 and earlier
Description: The issue allows mysql users to gain root privileges by creating world-writeable files and overwriting a configuration file using the "SELECT * INFO OUTFILE" operator. This can cause mysql to run as root upon restart, as demonstrated by modifying the my.cnf configuration file.
Recommendations: For MySQL versions 3.23.55 and earlier, consider restricting access to the SELECT * INFO OUTFILE operator until a fix is available. As a temporary workaround, restrict write access to configuration files, such as my.cnf, to prevent unauthorized modifications.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-0150

Affected Products

Mysql Server