CVE Database
/

CVE-2008-4098

Back to search

CVE-2008-4098

Published: Sep 17, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

MySQL before 5.0.67 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL home data directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4097.

VendorProductVersions

n/a

n/a

affected
n/a

References

MDVSA-2009:094
vendor-advisory
x_refsource_MANDRIVA
USN-1397-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2009:1067
vendor-advisory
x_refsource_REDHAT
USN-671-1
vendor-advisory
x_refsource_UBUNTU
38517
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:10591
vdb-entry
signature
x_refsource_OVAL
USN-897-1
vendor-advisory
x_refsource_UBUNTU
32769
third-party-advisory
x_refsource_SECUNIA
32759
third-party-advisory
x_refsource_SECUNIA
DSA-1662
vendor-advisory
x_refsource_DEBIAN
RHSA-2010:0110
vendor-advisory
x_refsource_REDHAT
SUSE-SR:2008:025
vendor-advisory
x_refsource_SUSE
32578
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now