LWN.net Logo

MySQL: privilege escalation

Package(s):MySQL CVE #(s):CAN-2004-0957
Created:April 14, 2005 Updated:April 20, 2005
Description: MySQL has a vulnerability in which a user with grant privileges can can grant privileges in other databases. In order to use this exploit, the database must have an underscore character in the name.
Alerts:
Conectiva CLA-2005:947 2005-04-20
Mandriva MDKSA-2005:070 2005-04-12

(Log in to post comments)

MySQL: privilege escalation

Posted Apr 23, 2005 14:01 UTC (Sat) by kreutzm (guest, #4700) [Link]

Debian is fixed as well, please see http://packages.qa.debian.org/m/mysql/news/2.html

and

http://www.debian.org/security/2005/dsa-707.

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds