Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2008-4097
Description:MySQL 5.0.51a allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are associated with symlinks within pathnames for subdirectories of the MySQL home data directory, which are followed when tables are created in the future. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-2079.
Test IDs: 1.3.6.1.4.1.25623.1.0.100156   1.3.6.1.4.1.25623.1.0.66425   1.3.6.1.4.1.25623.1.0.840292   1.3.6.1.4.1.25623.1.0.61910   1.3.6.1.4.1.25623.1.0.63872   1.3.6.1.4.1.25623.1.0.63095  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2008-4097
32759
http://secunia.com/advisories/32759
32769
http://secunia.com/advisories/32769
MDVSA-2009:094
http://www.mandriva.com/security/advisories?name=MDVSA-2009:094
SUSE-SR:2008:025
http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.html
USN-671-1
http://www.ubuntu.com/usn/USN-671-1
[oss-security] 20080909 Re: CVE request: MySQL incomplete fix for CVE-2008-2079
http://www.openwall.com/lists/oss-security/2008/09/09/20
[oss-security] 20080916 Re: CVE request: MySQL incomplete fix for CVE-2008-2079
http://www.openwall.com/lists/oss-security/2008/09/16/3
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=480292#25
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=480292#25
mysql-myisam-symlinks-security-bypass(45648)
https://exchange.xforce.ibmcloud.com/vulnerabilities/45648




© 1998-2025 E-Soft Inc. All rights reserved.