MySQL 5.1.x before 5.1.41 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL data home directory, related to incorrect calculation of the mysql_unpacked_real_data_home value. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4098 and CVE-2008-2079.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Mysql | — | Upgrade macOS to the latest version | Dec 16, 2011 | Nov 30, 2009 |
| Centos_linux | — | Upgrade mysql-develUpgrade mysql-serverUpgrade mysqlUpgrade mysql-benchUpgrade mysql-test | Dec 1, 2016 | Nov 30, 2009 |
| Oracle Mysql | — | Upgrade to Oracle MySQL version 5.1.41 | Aug 29, 2012 | Nov 30, 2009 |
| Oracle_linux | — | Upgrade mysql-serverUpgrade mysql-develUpgrade mysqlUpgrade mysql-benchUpgrade mysql-test | Oct 16, 2024 | Nov 30, 2009 |
| Suse | — | Upgrade mysql-MaxUpgrade mysql-sharedUpgrade libmysqld-develUpgrade mysql-ndb-managementUpgrade libmysqlclient16Upgrade mysql-shared-64bitUpgrade libmysqlclient15Upgrade mysql-toolsUpgrade mysql-benchUpgrade mysql-ndb-storageUpgrade mysql-ndb-toolsUpgrade libmysqlclient15-64bitUpgrade mysqlUpgrade mysql-develUpgrade mysql-shared-x86Upgrade mysql-ndb-extraUpgrade libmysqlclient_r15-32bitUpgrade libmysqlclient_r15Upgrade libmysqlclient15-32bitUpgrade mysql-shared-32bitUpgrade libmysqlclient-develUpgrade libmysqlclient16-32bitUpgrade mysql-clientUpgrade libmysqlclient15-x86Upgrade libmysqlclient_r16-32bitUpgrade libmysqlclient_r15-64bitUpgrade sap-aio-releaseUpgrade libmysqlclient_r16Upgrade mysql-debugUpgrade mysql-test | Feb 17, 2015 | Nov 30, 2009 |
| Ubuntu | — | Upgrade mysql-server-5.0Upgrade mysql-server-5.1 | Nov 8, 2024 | Nov 30, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub