MySQL 5.0.51a allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are associated with symlinks within pathnames for subdirectories of the MySQL home data directory, which are followed when tables are created in the future. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-2079.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2008-09-17T18:06:00

Updated: 2024-08-07T10:00:42.628Z

Reserved: 2008-09-15T00:00:00

Link: CVE-2008-4097

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2008-09-18T15:04:27.377

Modified: 2020-02-18T19:22:36.167

Link: CVE-2008-4097

cve-icon Redhat

No data.