Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.51887
Category:General
Title:MySQL Configuration Error
Summary:NOSUMMARY
Description:Description:

The installed version of MySQL, according to the version
number, is vulnerable to a configuration error that allows
an attacker with access to the database to possibly rewrite
the configuration file starting the daemon as root, which
would allow the attacker to gain elevated priviledges.

Versions up to and including 3.23.55 are known to be vulnerable.

Solution : Upgrade to 3.23.56 or later.
Risk factor : Critical

CVSS Score:
9.0

Cross-Ref: BugTraq ID: 7052
Common Vulnerability Exposure (CVE) ID: CVE-2003-0150
http://www.securityfocus.com/bid/7052
Bugtraq: 20030308 MySQL_user_can_be_changed_to_root? (Google Search)
http://marc.info/?l=bugtraq&m=104715840202315&w=2
Bugtraq: 20030310 Re: MySQL user can be changed to root (Google Search)
http://marc.info/?l=bugtraq&m=104739810523433&w=2
Bugtraq: 20030318 GLSA: mysql (200303-14) (Google Search)
http://marc.info/?l=bugtraq&m=104802285012750&w=2
Bugtraq: 20030318 [OpenPKG-SA-2003.022] OpenPKG Security Advisory (mysql) (Google Search)
http://marc.info/?l=bugtraq&m=104800948128630&w=2
CERT/CC vulnerability note: VU#203897
http://www.kb.cert.org/vuls/id/203897
Conectiva Linux advisory: CLA-2003:743
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000743
Debian Security Information: DSA-303 (Google Search)
http://www.debian.org/security/2003/dsa-303
En Garde Linux Advisory: ESA-20030324-012
http://www.linuxsecurity.com/advisories/engarde_advisory-3046.html
http://www.mandriva.com/security/advisories?name=MDKSA-2003:057
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A442
http://www.redhat.com/support/errata/RHSA-2003-093.html
RedHat Security Advisories: RHSA-2003:094
http://rhn.redhat.com/errata/RHSA-2003-094.html
XForce ISS Database: mysql-datadir-root-privileges(11510)
https://exchange.xforce.ibmcloud.com/vulnerabilities/11510
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2024 E-Soft Inc. All rights reserved.