[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

251139

 
 

909

 
 

196159

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2009-4030Date: (C)2009-11-30   (M)2024-02-22


MySQL 5.1.x before 5.1.41 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL data home directory, related to incorrect calculation of the mysql_unpacked_real_data_home value. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4098 and CVE-2008-2079.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.4
Exploit Score: 3.4
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECUNIA-38517
SECUNIA-38573
ADV-2010-1107
APPLE-SA-2010-03-29-1
DSA-1997
RHSA-2010:0109
RHSA-2010:0110
SUSE-SR:2010:011
SUSE-SR:2010:021
USN-1397-1
USN-897-1
http://lists.mysql.com/commits/89940
http://www.openwall.com/lists/oss-security/2009/11/19/3
http://marc.info/?l=oss-security&m=125908040022018&w=2
http://bugs.mysql.com/bug.php?id=32167
http://dev.mysql.com/doc/refman/5.1/en/news-5-1-41.html
http://support.apple.com/kb/HT4077
oval:org.mitre.oval:def:11116
oval:org.mitre.oval:def:8156

CPE    3
cpe:/a:mysql:mysql:5.1.23
cpe:/a:mysql:mysql:5.1.32
cpe:/a:mysql:mysql:5.1.5
CWE    1
CWE-59
OVAL    16
oval:org.secpod.oval:def:3875
oval:org.secpod.oval:def:200174
oval:org.secpod.oval:def:500459
oval:org.secpod.oval:def:200017
...

© SecPod Technologies