CVE

CVE-2008-2079

Severity:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
05/05/2008
Last modified:
17/12/2019

Description

MySQL 4.1.x before 4.1.24, 5.0.x before 5.0.60, 5.1.x before 5.1.24, and 6.0.x before 6.0.5 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are within the MySQL home data directory, which can point to tables that are created in the future.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mysql:mysql:*:*:*:*:*:*:*:* 4.1.0 (including) 4.1.24 (excluding)
cpe:2.3:a:mysql:mysql:*:*:*:*:*:*:*:* 5.0.0 (including) 5.0.60 (excluding)
cpe:2.3:a:mysql:mysql:*:*:*:*:*:*:*:* 5.1.0 (including) 5.1.24 (excluding)
cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:* 6.0.0 (including) 6.0.5 (excluding)
cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:7.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:lts:*:*:*


References to Advisories, Solutions, and Tools