Информационная безопасность
[RU] switch to
English Version



CVECVE-2008-4098
СтатусCandidate
ОписаниеMySQL before 5.0.67 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL home data directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4097.
PhaseAssigned (15.09.2008)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-4098
ReferencesCONFIRM : http://bugs.mysql.com/bug.php?id=32167
 MANDRIVA : MDVSA-2009:094
 MISC : http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=4...
 MLIST : [oss-security] 20080909 Re: CVE request: MySQL incomplete fix for CVE-2008-2079
 MLIST : [oss-security] 20080916 Re: CVE request: MySQL incomplete fix for CVE-2008-2079
 OVAL : oval:org.mitre.oval:def:10591
 REDHAT : RHSA-2009:1067
 REDHAT : RHSA-2010:0110
 SECUNIA : 32759
 SECUNIA : 38517
 SUSE : SUSE-SR:2008:025
 UBUNTU : USN-897-1
 XF : mysql-myisam-symlink-security-bypass(45649)
SecurityVulns:Повышение привилегий через MySQL
 Проблема с подгрузкой динамических функций в MySQL

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород

 
 



Rating@Mail.ru
test server