PT-2013-3572 · Oracle · Mysql Server

Vladz

·

Published

2013-08-19

·

Updated

2014-01-14

·

CVE-2013-2162

CVSS v2.0

1.9

Low

VectorAV:L/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions MySQL Server version 5.5
Description A race condition in the post-installation script for MySQL Server 5.5 creates a configuration file with world-readable permissions before restricting the permissions. This allows local users to read the file and obtain sensitive information, such as credentials.
Recommendations For MySQL Server version 5.5, consider restricting access to the configuration file until the permissions are properly set, or manually adjust the permissions to prevent unauthorized access. As a temporary workaround, restrict read access to the configuration file to minimize the risk of credential exposure.

Exploit

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-2162
DLA-75-1
DSA-2818-1

Affected Products

Mysql Server