Lucene search

K
freebsdFreeBSD8C451386-DFF3-11DD-A765-0030843D3802
HistoryNov 14, 2007 - 12:00 a.m.

mysql -- privilege escalation and overwrite of the system table information

2007-11-1400:00:00
vuxml.freebsd.org
16

7.1 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:S/C:C/I:C/A:C

0.028 Low

EPSS

Percentile

90.8%

MySQL reports:

Using RENAME TABLE against a table with explicit DATA
DIRECTORY and INDEX DIRECTORY options can be used to overwrite
system table information by replacing the symbolic link
points. the file to which the symlink points.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchmysql-server=Β 4.1UNKNOWN
FreeBSDanynoarchmysql-server<Β 4.1.24UNKNOWN

7.1 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:S/C:C/I:C/A:C

0.028 Low

EPSS

Percentile

90.8%