CVE-2008-4098
18.09.2008, 15:04
MySQL before 5.0.67 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL home data directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4097.
Vendor | Product | Version |
---|---|---|
canonical | ubuntu_linux | 6.06 |
canonical | ubuntu_linux | 7.10 |
canonical | ubuntu_linux | 8.04 |
canonical | ubuntu_linux | 8.10 |
canonical | ubuntu_linux | 9.04 |
canonical | ubuntu_linux | 9.10 |
debian | debian_linux | 5.0 |
mysql | mysql | 5.0.0 |
mysql | mysql | 5.0.1 |
mysql | mysql | 5.0.2 |
mysql | mysql | 5.0.3 |
mysql | mysql | 5.0.4 |
mysql | mysql | 5.0.5 |
mysql | mysql | 5.0.10 |
mysql | mysql | 5.0.15 |
mysql | mysql | 5.0.16 |
mysql | mysql | 5.0.17 |
mysql | mysql | 5.0.20 |
mysql | mysql | 5.0.24 |
mysql | mysql | 5.0.30 |
mysql | mysql | 5.0.36 |
mysql | mysql | 5.0.44 |
mysql | mysql | 5.0.54 |
mysql | mysql | 5.0.56 |
mysql | mysql | 5.0.60 |
mysql | mysql | 5.0.66 |
oracle | mysql | 5.0.23 |
oracle | mysql | 5.0.25 |
oracle | mysql | 5.0.26 |
oracle | mysql | 5.0.28 |
oracle | mysql | 5.0.30:sp1 |
oracle | mysql | 5.0.32 |
oracle | mysql | 5.0.34 |
oracle | mysql | 5.0.36:sp1 |
oracle | mysql | 5.0.38 |
oracle | mysql | 5.0.40 |
oracle | mysql | 5.0.41 |
oracle | mysql | 5.0.42 |
oracle | mysql | 5.0.44:sp1 |
oracle | mysql | 5.0.45 |
oracle | mysql | 5.0.46 |
oracle | mysql | 5.0.48 |
oracle | mysql | 5.0.50 |
oracle | mysql | 5.0.50:sp1 |
oracle | mysql | 5.0.51 |
oracle | mysql | 5.0.52 |
oracle | mysql | 5.0.56:sp1 |
oracle | mysql | 5.0.58 |
oracle | mysql | 5.0.60:sp1 |
oracle | mysql | 5.0.62 |
oracle | mysql | 5.0.64 |
oracle | mysql | 5.0.66:sp1 |
𝑥
= Vulnerable software versions

Ubuntu Releases
References