MySQL 3.23.55 and earlier creates world-writeable files and allows mysql users to gain root privileges by using the "SELECT * INFO OUTFILE" operator to overwrite a configuration file and cause mysql to run as root upon restart, as demonstrated by modifying my.cnf.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2003-03-21T05:00:00

Updated: 2024-08-08T01:43:36.037Z

Reserved: 2003-03-18T00:00:00

Link: CVE-2003-0150

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2003-03-24T05:00:00.000

Modified: 2024-11-20T23:44:05.730

Link: CVE-2003-0150

cve-icon Redhat

Severity : Important

Publid Date: 2003-03-08T00:00:00Z

Links: CVE-2003-0150 - Bugzilla