Lucene search

K
ubuntucveUbuntu.comUB:CVE-2005-0711
HistoryMay 02, 2005 - 12:00 a.m.

CVE-2005-0711

2005-05-0200:00:00
ubuntu.com
ubuntu.com
10

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

EPSS

0.001

Percentile

25.5%

MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, uses predictable file
names when creating temporary tables, which allows local users with CREATE
TEMPORARY TABLE privileges to overwrite arbitrary files via a symlink
attack.

OSVersionArchitecturePackageVersionFilename
ubuntu6.06noarchmysql-dfsg< 4.0.24-10ubuntu2UNKNOWN
ubuntu6.10noarchmysql-dfsg< 4.0.24-10ubuntu2UNKNOWN
ubuntu6.06noarchmysql-dfsg-4.1< 4.1.15-1ubuntu5UNKNOWN
ubuntu6.10noarchmysql-dfsg-4.1< 4.1.15-1ubuntu5UNKNOWN
ubuntu6.06noarchmysql-dfsg-5.0< 5.0.22-0ubuntu6.06.3UNKNOWN
ubuntu6.10noarchmysql-dfsg-5.0< 5.0.24a-9ubuntu0.1UNKNOWN
ubuntu7.04noarchmysql-dfsg-5.0< 5.0.38-0ubuntu1UNKNOWN

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

EPSS

0.001

Percentile

25.5%