PT-2012-5408 · Oracle+1 · Mysql Server+1
Karel Volný
+1
·
Published
2012-10-09
·
Updated
2023-02-13
·
CVE-2012-4452
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
MySQL versions 5.0.88 and possibly other versions
Description
The issue allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified
DATA DIRECTORY or INDEX DIRECTORY arguments. These arguments can point to tables created at a future time, allowing a pathname to be modified to contain a symlink to a subdirectory of the MySQL data home directory. This is related to incorrect calculation of the mysql unpacked real data home value.Recommendations
For MySQL version 5.0.88, consider restricting the use of the CREATE TABLE statement with modified
DATA DIRECTORY or INDEX DIRECTORY arguments until a patch is available.
For other possibly affected versions, at the moment, there is no information about a newer version that contains a fix for this issue.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mysql Server
Red Hat