CVE Vulnerabilities

CVE-2005-1636

Published: May 17, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

mysql_install_db in MySQL 4.1.x before 4.1.12 and 5.x up to 5.0.4 creates the mysql_install_db.X file with a predictable filename and insecure permissions, which allows local users to execute arbitrary SQL commands by modifying the files contents.

Affected Software

NameVendorStart VersionEnd Version
MysqlMysql5.0.1 (including)5.0.1 (including)
MysqlMysql5.0.2 (including)5.0.2 (including)
MysqlMysql5.0.3 (including)5.0.3 (including)
MysqlMysql5.0.4 (including)5.0.4 (including)
MysqlOracle4.0.0 (including)4.0.0 (including)
MysqlOracle4.0.1 (including)4.0.1 (including)
MysqlOracle4.0.2 (including)4.0.2 (including)
MysqlOracle4.0.3 (including)4.0.3 (including)
MysqlOracle4.0.4 (including)4.0.4 (including)
MysqlOracle4.0.5 (including)4.0.5 (including)
MysqlOracle4.0.5a (including)4.0.5a (including)
MysqlOracle4.0.6 (including)4.0.6 (including)
MysqlOracle4.0.7 (including)4.0.7 (including)
MysqlOracle4.0.7-gamma (including)4.0.7-gamma (including)
MysqlOracle4.0.8 (including)4.0.8 (including)
MysqlOracle4.0.8-gamma (including)4.0.8-gamma (including)
MysqlOracle4.0.9 (including)4.0.9 (including)
MysqlOracle4.0.9-gamma (including)4.0.9-gamma (including)
MysqlOracle4.0.10 (including)4.0.10 (including)
MysqlOracle4.0.11 (including)4.0.11 (including)
MysqlOracle4.0.11-gamma (including)4.0.11-gamma (including)
MysqlOracle5.0.0-alpha (including)5.0.0-alpha (including)
Red Hat Enterprise Linux 4RedHatmysql-0:4.1.12-3.RHEL4.1*

References