CVE Vulnerabilities

CVE-2008-2079

Published: May 05, 2008 | Modified: Dec 17, 2019
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:N/AC:H/Au:S/C:P/I:P/A:P
RedHat/V2
4.9 MODERATE
AV:N/AC:M/Au:S/C:P/I:P/A:N
RedHat/V3
Ubuntu
LOW

MySQL 4.1.x before 4.1.24, 5.0.x before 5.0.60, 5.1.x before 5.1.24, and 6.0.x before 6.0.5 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are within the MySQL home data directory, which can point to tables that are created in the future.

Affected Software

Name Vendor Start Version End Version
Mysql Mysql 4.1.0 (including) 4.1.24 (excluding)
Mysql Mysql 5.0.0 (including) 5.0.60 (excluding)
Mysql Mysql 5.1.0 (including) 5.1.24 (excluding)
Mysql Oracle 6.0.0 (including) 6.0.5 (excluding)
Red Hat Enterprise Linux 4 RedHat mysql-0:4.1.22-2.el4 *
Red Hat Enterprise Linux 5 RedHat mysql-0:5.0.77-3.el5 *
Red Hat Web Application Stack for RHEL 4 RedHat httpd-0:2.0.63-2.el4s1.2 *
Red Hat Web Application Stack for RHEL 4 RedHat mod_jk-0:1.2.26-1.el4s1.1 *
Red Hat Web Application Stack for RHEL 4 RedHat mysql-0:5.0.50sp1a-2.el4s1.1 *
Red Hat Web Application Stack for RHEL 4 RedHat mysql-connector-odbc-0:3.51.24r1071-1.el4s1.1 *
Red Hat Web Application Stack for RHEL 4 RedHat perl-DBD-MySQL-0:4.006-1.el4 *
Red Hat Web Application Stack for RHEL 4 RedHat perl-DBI-0:1.604-1.el4s1 *
Red Hat Web Application Stack for RHEL 4 RedHat php-0:5.1.6-3.el4s1.9 *
Red Hat Web Application Stack for RHEL 4 RedHat postgresqlclient7-0:7.4.19-1.el4s1.1 *
Red Hat Web Application Stack for RHEL 4 RedHat postgresql-jdbc-0:8.1.412-1jpp.el4s1.1 *
Red Hat Web Application Stack for RHEL 4 RedHat unixODBC-0:2.2.12-6.el4s1.1 *
Mysql-dfsg-5.0 Ubuntu dapper *
Mysql-dfsg-5.0 Ubuntu feisty *
Mysql-dfsg-5.0 Ubuntu gutsy *
Mysql-dfsg-5.0 Ubuntu hardy *
Mysql-dfsg-5.0 Ubuntu upstream *

References