CVE-2009-4030

EUVD-2009-4001
MySQL 5.1.x before 5.1.41 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL data home directory, related to incorrect calculation of the mysql_unpacked_real_data_home value.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4098 and CVE-2008-2079.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.4 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 7%
Affected Products (NVD)
VendorProductVersion
mysqlmysql
5.1.5
mysqlmysql
5.1.23
mysqlmysql
5.1.32
oraclemysql
5.1
oraclemysql
5.1.1
oraclemysql
5.1.2
oraclemysql
5.1.3
oraclemysql
5.1.4
oraclemysql
5.1.6
oraclemysql
5.1.7
oraclemysql
5.1.8
oraclemysql
5.1.9
oraclemysql
5.1.10
oraclemysql
5.1.11
oraclemysql
5.1.12
oraclemysql
5.1.13
oraclemysql
5.1.14
oraclemysql
5.1.15
oraclemysql
5.1.16
oraclemysql
5.1.17
oraclemysql
5.1.18
oraclemysql
5.1.19
oraclemysql
5.1.20
oraclemysql
5.1.21
oraclemysql
5.1.22
oraclemysql
5.1.30
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
mysql-5.1
dapper
dne
hardy
dne
jaunty
dne
karmic
dne
lucid
dne
maverick
Fixed 5.1.41-3ubuntu7
released
natty
Fixed 5.1.41-3ubuntu7
released
mysql-dfsg
dapper
ignored
hardy
dne
intrepid
dne
jaunty
dne
karmic
dne
lucid
dne
maverick
dne
natty
dne
mysql-dfsg-4.1
dapper
ignored
hardy
dne
intrepid
dne
jaunty
dne
karmic
dne
lucid
dne
maverick
dne
natty
dne
mysql-dfsg-5.0
dapper
Fixed 5.0.22-0ubuntu6.06.12
released
hardy
Fixed 5.0.51a-3ubuntu5.5
released
intrepid
Fixed 5.0.67-0ubuntu6.1
released
jaunty
Fixed 5.1.30really5.0.75-0ubuntu10.3
released
karmic
ignored
lucid
dne
maverick
dne
natty
dne
mysql-dfsg-5.1
dapper
dne
hardy
dne
intrepid
dne
jaunty
ignored
karmic
Fixed 5.1.37-1ubuntu5.1
released
lucid
Fixed 5.1.41-3ubuntu7
released
maverick
dne
natty
dne
References