MySQL 5.1.x before 5.1.41 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL data home directory, related to incorrect calculation of the mysql_unpacked_real_data_home value. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4098 and CVE-2008-2079.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Mysql | — | Upgrade macOS to the latest version | Dec 16, 2011 | Nov 30, 2009 |
| Centos_linux | — | Upgrade mysql-benchUpgrade mysql-testUpgrade mysqlUpgrade mysql-serverUpgrade mysql-devel | Dec 1, 2016 | Nov 30, 2009 |
| Oracle Mysql | — | Upgrade to Oracle MySQL version 5.1.41 | Aug 29, 2012 | Nov 30, 2009 |
| Oracle_linux | — | Upgrade mysql-serverUpgrade mysql-develUpgrade mysql-testUpgrade mysql-benchUpgrade mysql | Oct 16, 2024 | Nov 30, 2009 |
| Suse | — | Upgrade mysqlUpgrade mysql-ndb-storageUpgrade libmysqlclient16Upgrade libmysqlclient15Upgrade mysql-ndb-toolsUpgrade mysql-shared-64bitUpgrade mysql-develUpgrade mysql-shared-x86Upgrade mysql-sharedUpgrade mysql-MaxUpgrade libmysqlclient15-64bitUpgrade libmysqlclient15-32bitUpgrade mysql-toolsUpgrade mysql-shared-32bitUpgrade mysql-benchUpgrade libmysqld-develUpgrade libmysqlclient_r15Upgrade libmysqlclient_r15-32bitUpgrade mysql-ndb-extraUpgrade mysql-ndb-managementUpgrade libmysqlclient16-32bitUpgrade sap-aio-releaseUpgrade libmysqlclient_r16-32bitUpgrade libmysqlclient_r15-64bitUpgrade libmysqlclient_r16Upgrade mysql-testUpgrade mysql-debugUpgrade libmysqlclient15-x86Upgrade mysql-clientUpgrade libmysqlclient-devel | Feb 17, 2015 | Nov 30, 2009 |
| Ubuntu | — | Upgrade mysql-server-5.1Upgrade mysql-server-5.0 | Nov 8, 2024 | Nov 30, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub