CVE-ID |
CVE-2012-4452
|
• CVSS Severity Rating • Fix Information • Vulnerable Software Versions • SCAP Mappings • CPE Information
|
Description |
MySQL 5.0.88, and possibly other versions and platforms, allows local
users to bypass certain privilege checks by calling CREATE TABLE on a
MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY
arguments that are originally associated with pathnames without
symlinks, and that can point to tables created at a future time at
which a pathname is modified to contain a symlink to a subdirectory of
the MySQL data home directory, related to incorrect calculation of the
mysql_unpacked_real_data_home value. NOTE: this vulnerability exists
because of a CVE-2009-4030 regression, which was not omitted in other
packages and versions such as MySQL 5.0.95 in Red Hat Enterprise Linux
6.
|
References |
Note: References are provided for the convenience of the reader to help distinguish between vulnerabilities. The list is not intended to be complete.
|
|
Assigning CNA |
N/A |
Date Entry Created |
20120821 |
Disclaimer: The entry creation date may reflect when
the CVE ID was allocated or reserved, and does not
necessarily indicate when this vulnerability was
discovered, shared with the affected vendor, publicly
disclosed, or updated in CVE.
|
Phase (Legacy) |
Assigned (20120821) |
Votes (Legacy) |
|
Comments (Legacy) |
|
Proposed (Legacy) |
N/A |
This is an entry on the CVE List, which provides common identifiers for publicly known cybersecurity vulnerabilities. |
|
For More Information: cve@mitre.org
|