[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-1662 mysql-dfsg-5.0 -- authorization bypass

ID: oval:org.mitre.oval:def:7628Date: (C)2009-12-15   (M)2023-12-07
Class: PATCHFamily: unix




A symlink traversal vulnerability was discovered in MySQL, a relational database server. The weakness could permit an attacker having both CREATE TABLE access to a database and the ability to execute shell commands on the database server to bypass MySQL access controls, enabling them to write to tables in databases to which they would not ordinarily have access. The Common Vulnerabilities and Exposures project identifies this vulnerability as CVE-2008-4098. Note that a closely aligned issue, identified as CVE-2008-4097, was prevented by the update announced in DSA-1608-1. This new update supersedes that fix and mitigates both potential attack vectors.

Platform:
Debian 4.0
Product:
mysql-dfsg-5.0
Reference:
DSA-1662
CVE-2008-4098
CVE-2008-4097
CVE    2
CVE-2008-4097
CVE-2008-4098
CPE    1
cpe:/o:debian:debian_linux:4.0

© SecPod Technologies