MySQL 5.0.51a allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are associated with symlinks within pathnames for subdirectories of the MySQL home data directory, which are followed when tables are created in the future. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-2079.
Advisories
Source ID Title
Debian DSA Debian DSA DSA-1662-1 New mysql-dfsg-5.0 packages fix authorization bypass
EUVD EUVD EUVD-2008-4081 MySQL 5.0.51a allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are associated with symlinks within pathnames for subdirectories of the MySQL home data directory, which are followed when tables are created in the future. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-2079.
Ubuntu USN Ubuntu USN USN-671-1 MySQL vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-07T10:00:42.628Z

Reserved: 2008-09-15T00:00:00

Link: CVE-2008-4097

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2008-09-18T15:04:27.377

Modified: 2025-04-09T00:30:58.490

Link: CVE-2008-4097

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses