LWN.net Logo

mysql: access restriction bypass

Package(s):mysql CVE #(s):CVE-2008-7247
Created:February 2, 2010 Updated:November 16, 2010
Description: From the CVE entry:

sql/sql_table.cc in MySQL 5.0.x through 5.0.88, 5.1.x through 5.1.41, and 6.0 before 6.0.9-alpha, when the data home directory contains a symlink to a different filesystem, allows remote authenticated users to bypass intended access restrictions by calling CREATE TABLE with a (1) DATA DIRECTORY or (2) INDEX DIRECTORY argument referring to a subdirectory that requires following this symlink.

Alerts:
SUSE SUSE-SR:2010:021 2010-11-16
Pardus 2010-73 2010-06-04
SuSE SUSE-SR:2010:011 2010-05-10
SuSE SUSE-SR:2010:007 2010-03-30
Mandriva MDVSA-2010:044 2010-02-19
Pardus 2010-29 2010-02-09
Ubuntu USN-897-1 2010-02-10
Fedora FEDORA-2010-1348 2010-02-02
Fedora FEDORA-2010-1300 2010-02-02
Gentoo 201201-02 2012-01-05
Ubuntu USN-1397-1 2012-03-12

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds