PT-2005-2613 · Oracle+1 · Mysql Server+1

Josh Bressers

·

Published

2005-05-17

·

Updated

2019-12-17

·

CVE-2005-1636

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MySQL versions 4.1.x up to 4.1.11 MySQL versions 5.x up to 5.0.4
Description The issue allows local users to execute arbitrary SQL commands by modifying the contents of a file created by mysql install db. This is due to the file being created with a predictable filename and insecure permissions.
Recommendations For MySQL versions 4.1.x up to 4.1.11, update to version 4.1.12 or later. For MySQL versions 5.x up to 5.0.4, update to version 5.0.5 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-1636
DSA-783-1
RHSA-2005:685
RHSA-2005_685

Affected Products

Mysql Server
Red Hat