PT-2008-5401 · Oracle+1 · Mysql Server+1

Devin Carraway

·

Published

2008-09-17

·

Updated

2019-12-17

·

CVE-2008-4098

CVSS v2.0

4.6

Medium

VectorAV:N/AC:H/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MySQL versions prior to 5.0.67
Description The issue allows local users to bypass certain privilege checks by exploiting the CREATE TABLE functionality on MyISAM tables. This is achieved by modifying the DATA DIRECTORY or INDEX DIRECTORY arguments to point to tables that can be created at a future time, potentially allowing access to subdirectories of the MySQL home data directory through symlinks.
Recommendations For MySQL versions prior to 5.0.67, update to version 5.0.67 or later to resolve the issue.

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-4098
DSA-1662-1
RHSA-2009:1067
RHSA-2010:0110
RHSA-2010_0110

Affected Products

Mysql Server
Red Hat