PT-2009-2714 · Oracle · Mysql Server

Jan Lieskovsky

·

Published

2009-11-30

·

Updated

2024-06-15

·

CVE-2008-7247

CVSS v2.0

6.0

Medium

VectorAV:N/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MySQL versions 5.0.x through 5.0.88 MySQL versions 5.1.x through 5.1.41 MySQL version 6.0 before 6.0.9-alpha
Description The issue allows remote authenticated users to bypass intended access restrictions. This occurs when the data home directory contains a symlink to a different filesystem, and the user calls CREATE TABLE with a DATA DIRECTORY or INDEX DIRECTORY argument referring to a subdirectory that requires following this symlink.
Recommendations For MySQL versions 5.0.x through 5.0.88, update to a version after 5.0.88 to resolve the issue. For MySQL versions 5.1.x through 5.1.41, update to a version after 5.1.41 to resolve the issue. For MySQL version 6.0 before 6.0.9-alpha, update to version 6.0.9-alpha or later to resolve the issue.

Exploit

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-7247
OPENSUSE-SU-2024:10153-1
SUSE-RU-2023:3956-1
SUSE-RU-2023:4991-1

Affected Products

Mysql Server