PT-2012-5408 · Oracle+1 · Mysql Server+1

Karel Volný

+1

·

Published

2012-10-09

·

Updated

2023-02-13

·

CVE-2012-4452

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions MySQL versions 5.0.88 and possibly other versions
Description The issue allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified DATA DIRECTORY or INDEX DIRECTORY arguments. These arguments can point to tables created at a future time, allowing a pathname to be modified to contain a symlink to a subdirectory of the MySQL data home directory. This is related to incorrect calculation of the mysql unpacked real data home value.
Recommendations For MySQL version 5.0.88, consider restricting the use of the CREATE TABLE statement with modified DATA DIRECTORY or INDEX DIRECTORY arguments until a patch is available. For other possibly affected versions, at the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Weakness Enumeration

Related Identifiers

CVE-2012-4452
RHSA-2013:0121
RHSA-2013_0121

Affected Products

Mysql Server
Red Hat