| |||||||||||||
| CVE Kennung: | CAN-2004-0457 |
| Beschreibung: | The mysqlhotcopy script in mysql 4.0.20 and earlier, when using the scp method from the mysql-server package, allows local users to overwrite arbitrary files via a symlink attack on temporary files. |
| Test Kennungen: | Nicht verfügbar |
| Querverweise: |
Common Vulnerability Exposure (CVE) ID: CVE-2004-0457 Debian Security Information: DSA-540 (Google Search) http://www.debian.org/security/2004/dsa-540 RedHat Security Advisories: RHSA-2004:597 http://www.redhat.com/support/errata/RHSA-2004-597.html Computer Incident Advisory Center Bulletin: P-018 http://www.ciac.org/ciac/bulletins/p-018.shtml http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10693 XForce ISS Database: mysql-mysqlhotcopy-insecure-file(17030) http://xforce.iss.net/xforce/xfdb/17030 |
|