PT-2005-1141 · Oracle+2 · Mysql Server+2

Javier Fernandez-Sanguino Pena

·

Published

2005-01-20

·

Updated

2022-08-05

·

CVE-2005-0004

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MySQL versions 3.x and earlier MySQL versions 4.0.23 and earlier MySQL versions 4.1.x before 4.1.10 MySQL versions 5.0.x before 5.0.3
Description The issue allows local users to overwrite arbitrary files or read temporary files via a symlink attack on temporary files created by the mysqlaccess script.
Recommendations For MySQL versions 3.x and earlier, update to a version later than 3.x to resolve the issue. For MySQL versions 4.0.23 and earlier, update to a version later than 4.0.23 to resolve the issue. For MySQL versions 4.1.x before 4.1.10, update to version 4.1.10 or later to resolve the issue. For MySQL versions 5.0.x before 5.0.3, update to version 5.0.3 or later to resolve the issue.

Fix

Link Following

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1749
CVE-2005-0004
DSA-647-1

Affected Products

Alt Linux
Mariadb Server
Mysql Server