Lucene search

K
ubuntucveUbuntu.comUB:CVE-2005-0709
HistoryMay 02, 2005 - 12:00 a.m.

CVE-2005-0709

2005-05-0200:00:00
ubuntu.com
ubuntu.com
14

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.968

Percentile

99.7%

MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote
authenticated users with INSERT and DELETE privileges to execute arbitrary
code by using CREATE FUNCTION to access libc calls, as demonstrated by
using strcat, on_exit, and exit.

OSVersionArchitecturePackageVersionFilename
ubuntu6.06noarchmysql-dfsg< 4.0.24-10ubuntu2UNKNOWN
ubuntu6.10noarchmysql-dfsg< 4.0.24-10ubuntu2UNKNOWN
ubuntu6.06noarchmysql-dfsg-4.1< 4.1.15-1ubuntu5UNKNOWN
ubuntu6.10noarchmysql-dfsg-4.1< 4.1.15-1ubuntu5UNKNOWN
ubuntu6.06noarchmysql-dfsg-5.0< 5.0.22-0ubuntu6.06.3UNKNOWN
ubuntu6.10noarchmysql-dfsg-5.0< 5.0.24a-9ubuntu0.1UNKNOWN
ubuntu7.04noarchmysql-dfsg-5.0< 5.0.38-0ubuntu1UNKNOWN

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.968

Percentile

99.7%