CVE-2009-4030

MySQL 5.1.x before 5.1.41 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL data home directory, related to incorrect calculation of the mysql_unpacked_real_data_home value.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4098 and CVE-2008-2079.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.4 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:N/C:P/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 10%
VendorProductVersion
mysqlmysql
5.1.5
mysqlmysql
5.1.23
mysqlmysql
5.1.32
oraclemysql
5.1
oraclemysql
5.1.1
oraclemysql
5.1.2
oraclemysql
5.1.3
oraclemysql
5.1.4
oraclemysql
5.1.6
oraclemysql
5.1.7
oraclemysql
5.1.8
oraclemysql
5.1.9
oraclemysql
5.1.10
oraclemysql
5.1.11
oraclemysql
5.1.12
oraclemysql
5.1.13
oraclemysql
5.1.14
oraclemysql
5.1.15
oraclemysql
5.1.16
oraclemysql
5.1.17
oraclemysql
5.1.18
oraclemysql
5.1.19
oraclemysql
5.1.20
oraclemysql
5.1.21
oraclemysql
5.1.22
oraclemysql
5.1.30
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
mysql-5.1
natty
Fixed 5.1.41-3ubuntu7
released
maverick
Fixed 5.1.41-3ubuntu7
released
lucid
dne
karmic
dne
jaunty
dne
hardy
dne
dapper
dne
mysql-dfsg
natty
dne
maverick
dne
lucid
dne
karmic
dne
jaunty
dne
intrepid
dne
hardy
dne
dapper
ignored
mysql-dfsg-4.1
natty
dne
maverick
dne
lucid
dne
karmic
dne
jaunty
dne
intrepid
dne
hardy
dne
dapper
ignored
mysql-dfsg-5.0
natty
dne
maverick
dne
lucid
dne
karmic
ignored
jaunty
Fixed 5.1.30really5.0.75-0ubuntu10.3
released
intrepid
Fixed 5.0.67-0ubuntu6.1
released
hardy
Fixed 5.0.51a-3ubuntu5.5
released
dapper
Fixed 5.0.22-0ubuntu6.06.12
released
mysql-dfsg-5.1
natty
dne
maverick
dne
lucid
Fixed 5.1.41-3ubuntu7
released
karmic
Fixed 5.1.37-1ubuntu5.1
released
jaunty
ignored
intrepid
dne
hardy
dne
dapper
dne
References