Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2008-4097 (mysql)

BugsAlert Home > CVE-2008-4097 (mysql)
 
 

MySQL 5.0.51a allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are associated with symlinks within pathnames for subdirectories of the MySQL home data directory, which are followed when tables are created in the future. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-2079.




Original Source: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-4097

Learn more about CVE-2008-4097 (mysql)
 
Tags: cve-2008-4097 mysql

Related Items

      FrSIRT - Link ADS "linkid" Parameter Remote SQL Injection Vulnerability

      Vuln: E-topbiz eStore 'index.php' SQL Injection Vulnerability

      CVE-2008-3285 (filesys_smbclientparser)

      For Sale: Premodded Video Game Consoles, Backups & Retro S..

      shoutbox Remote Password Disclouse Vulnerability

      BtitTracker Multiple Vulnerabilities

      FrSIRT - Mandriva Security Update Fixes GNU ed Buffer Overflow Vulnerability

 

Pixel