Lucene search

K
ubuntucveUbuntu.comUB:CVE-2009-4030
HistoryNov 30, 2009 - 12:00 a.m.

CVE-2009-4030

2009-11-3000:00:00
ubuntu.com
ubuntu.com
19

CVSS2

4.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:S/C:P/I:P/A:P

EPSS

0

Percentile

16.1%

MySQL 5.1.x before 5.1.41 allows local users to bypass certain privilege
checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA
DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated
with pathnames without symlinks, and that can point to tables created at a
future time at which a pathname is modified to contain a symlink to a
subdirectory of the MySQL data home directory, related to incorrect
calculation of the mysql_unpacked_real_data_home value. NOTE: this
vulnerability exists because of an incomplete fix for CVE-2008-4098 and
CVE-2008-2079.

Bugs

Notes

Author Note
mdeslaur actually made it in 5.1.42
OSVersionArchitecturePackageVersionFilename
ubuntu10.10noarchmysql-5.1<Β 5.1.41-3ubuntu7UNKNOWN
ubuntu11.04noarchmysql-5.1<Β 5.1.41-3ubuntu7UNKNOWN
ubuntu6.06noarchmysql-dfsg-5.0<Β 5.0.22-0ubuntu6.06.12UNKNOWN
ubuntu8.04noarchmysql-dfsg-5.0<Β 5.0.51a-3ubuntu5.5UNKNOWN
ubuntu8.10noarchmysql-dfsg-5.0<Β 5.0.67-0ubuntu6.1UNKNOWN
ubuntu9.04noarchmysql-dfsg-5.0<Β 5.1.30really5.0.75-0ubuntu10.3UNKNOWN
ubuntu9.10noarchmysql-dfsg-5.1<Β 5.1.37-1ubuntu5.1UNKNOWN
ubuntu10.04noarchmysql-dfsg-5.1<Β 5.1.41-3ubuntu7UNKNOWN

CVSS2

4.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:S/C:P/I:P/A:P

EPSS

0

Percentile

16.1%