The mysqlhotcopy script in mysql 4.0.20 and earlier, when using the scp method from the mysql-server package, allows local users to overwrite arbitrary files via a symlink attack on temporary files.
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade mysql-scripts | Dec 10, 2025 | Aug 22, 2004 |
| Gentoo Linux | — | Upgrade dev-db/mysql. | Oct 30, 2017 | Sep 28, 2004 |
| Oracle Mysql | — | Upgrade to the latest version of MySQL | Aug 29, 2012 | Sep 28, 2004 |
| Suse | — | Upgrade mysql | Dec 12, 2013 | Sep 28, 2004 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub