Lucene search

K
freebsdFreeBSDA0E92718-6603-11DB-AB90-000E35FD8194
HistoryAug 09, 2006 - 12:00 a.m.

mysql -- database "case-sensitive" privilege escalation

2006-08-0900:00:00
vuxml.freebsd.org
15

CVSS2

3.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:S/C:P/I:P/A:N

EPSS

0.005

Percentile

75.9%

Michal Prokopiuk reports a privilege escalation in MySQL.
The vulnerability causes MySQL, when run on case-sensitive
filesystems, to allow remote and local authenticated users
to create or access a database when the database name
differs only in case from a database for which they have
permissions.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchmysql-server= 5.1UNKNOWN
FreeBSDanynoarchmysql-server< 5.1.12UNKNOWN

CVSS2

3.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:S/C:P/I:P/A:N

EPSS

0.005

Percentile

75.9%