MySQL 5.0.51a allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are associated with symlinks within pathnames for subdirectories of the MySQL home data directory, which are followed when tables are created in the future. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-2079.
CVSS Details
- CVSS 3.1 Base Score: 7.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade mysql-server | Dec 10, 2025 | Dec 30, 2008 |
| Gentoo Linux | — | Upgrade dev-db/mysql. | Oct 30, 2017 | Sep 18, 2008 |
| Suse | — | Upgrade libmysqlclient_r15-32bitUpgrade suse-releaseUpgrade mysql-shared-x86Upgrade mysql-sharedUpgrade libmysqlclient15-64bitUpgrade mysql-develUpgrade libmysqlclient_r15Upgrade mysql-debugUpgrade mysql-benchUpgrade mysqlUpgrade libmysqlclient15-32bitUpgrade libmysqlclient-develUpgrade mysql-shared-64bitUpgrade mysql-MaxUpgrade mysql-clientUpgrade libmysqlclient15Upgrade mysql-toolsUpgrade libmysqlclient_r15-64bitUpgrade mysql-shared-32bit | Feb 17, 2015 | Sep 18, 2008 |
| Ubuntu | — | Upgrade mysql-server-5.0 | Nov 8, 2024 | Sep 18, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub