CVE-2004-0957
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/02/2005
Last modified:
03/04/2025
Description
Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database whose name includes a "_" (underscore), grants privileges to other databases that have similar names, which can allow the user to conduct unauthorized activities.
Impact
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:openpkg:openpkg:2.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:openpkg:openpkg:2.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:openpkg:openpkg:current:*:*:*:*:*:*:* | ||
| cpe:2.3:a:oracle:mysql:3.20:*:*:*:*:*:*:* | ||
| cpe:2.3:a:oracle:mysql:3.20.32a:*:*:*:*:*:*:* | ||
| cpe:2.3:a:oracle:mysql:3.21:*:*:*:*:*:*:* | ||
| cpe:2.3:a:oracle:mysql:3.22:*:*:*:*:*:*:* | ||
| cpe:2.3:a:oracle:mysql:3.22.26:*:*:*:*:*:*:* | ||
| cpe:2.3:a:oracle:mysql:3.22.27:*:*:*:*:*:*:* | ||
| cpe:2.3:a:oracle:mysql:3.22.28:*:*:*:*:*:*:* | ||
| cpe:2.3:a:oracle:mysql:3.22.29:*:*:*:*:*:*:* | ||
| cpe:2.3:a:oracle:mysql:3.22.30:*:*:*:*:*:*:* | ||
| cpe:2.3:a:oracle:mysql:3.22.32:*:*:*:*:*:*:* | ||
| cpe:2.3:a:oracle:mysql:3.23:*:*:*:*:*:*:* | ||
| cpe:2.3:a:oracle:mysql:3.23.2:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000947
- http://www.ciac.org/ciac/bulletins/p-018.shtml
- http://www.debian.org/security/2005/dsa-707
- http://www.mandriva.com/security/advisories?name=MDKSA-2005%3A070
- http://www.redhat.com/support/errata/RHSA-2004-597.html
- http://www.redhat.com/support/errata/RHSA-2004-611.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17783
- https://www.ubuntu.com/usn/usn-32-1/
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000947
- http://www.ciac.org/ciac/bulletins/p-018.shtml
- http://www.debian.org/security/2005/dsa-707
- http://www.mandriva.com/security/advisories?name=MDKSA-2005%3A070
- http://www.redhat.com/support/errata/RHSA-2004-597.html
- http://www.redhat.com/support/errata/RHSA-2004-611.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17783
- https://www.ubuntu.com/usn/usn-32-1/



