MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the FILE privilege to users who should not have administrative privileges, allows remote authenticated users to gain privileges by leveraging the FILE privilege to create files as the MySQL administrator. NOTE: the vendor disputes this issue, stating that this is only a vulnerability when the administrator does not follow recommendations in the product's installation documentation. NOTE: it could be argued that this should not be included in CVE because it is a configuration issue.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade dev-db/mysql. | Oct 30, 2017 | Dec 3, 2012 |
| Suse | — | Upgrade sle-sdk-releaseUpgrade libmysqlclient-develUpgrade libmysqlclient_r15Upgrade mysql-MaxUpgrade mysql-toolsUpgrade libmysqlclient15-x86Upgrade libmysqlclient_r15-32bitUpgrade libmysqlclient15Upgrade libmysqlclient_r15-x86Upgrade mysql-clientUpgrade libmysqlclient15-32bitUpgrade mysql | Feb 17, 2015 | Dec 3, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub