Lucene search

K
ubuntucveUbuntu.comUB:CVE-2012-4452
HistoryOct 09, 2012 - 12:00 a.m.

CVE-2012-4452

2012-10-0900:00:00
ubuntu.com
ubuntu.com
21

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.001

Percentile

26.5%

MySQL 5.0.88, and possibly other versions and platforms, allows local users
to bypass certain privilege checks by calling CREATE TABLE on a MyISAM
table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments
that are originally associated with pathnames without symlinks, and that
can point to tables created at a future time at which a pathname is
modified to contain a symlink to a subdirectory of the MySQL data home
directory, related to incorrect calculation of the
mysql_unpacked_real_data_home value. NOTE: this vulnerability exists
because of a CVE-2009-4030 regression, which was not omitted in other
packages and versions such as MySQL 5.0.95 in Red Hat Enterprise Linux 6.

Bugs

Notes

Author Note
jdstrand As of 2012/01/09, Oracle no longer supports MySQL 5.0. Unfortunately, because of upstream update and commit policies it is not possible to backport patches from later releases. Ubuntu is regrettably unable to support MySQL 5.0 and users are encouraged to upgrade to Ubuntu 10.04 LTS or later.

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.001

Percentile

26.5%