MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, uses predictable file names when creating temporary tables, which allows local users with CREATE TEMPORARY TABLE privileges to overwrite arbitrary files via a symlink attack.
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Mysql | — | Apply OS X security update 2005-007 | Dec 16, 2011 | May 2, 2005 |
| Freebsd | — | Upgrade mysql-server | Dec 10, 2025 | Mar 14, 2005 |
| Gentoo Linux | — | Upgrade dev-db/mysql. | Oct 30, 2017 | May 2, 2005 |
| Suse | — | Upgrade mysql-MaxUpgrade mysql | Feb 17, 2015 | May 2, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub