Definition


New Search

MySQL 5.1 Privilege Bypass with DATA/INDEX DIRECTORY

oval:org.mitre.oval:def:8156

MySQL 5.1.x before 5.1.41 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL data home directory related to incorrect calculation of the mysql_unpacked_real_data_home value. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4098 and CVE-2008-2079.

Family:
windows
Status:
ACCEPTED
Platform(s):
  • Microsoft Windows Server 2003
  • Microsoft Windows Vista
  • Microsoft Windows Server 2008
  • Microsoft Windows XP
  • Microsoft Windows 7
  • Microsoft Windows 2000
Class:
vulnerability
Reference(s):
  • CVE-2009-4030
Product(s):
  • MySQL Server 5.1