~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to retired/CVE-2008-4097

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
Candidate: CVE-2008-4097
2
 
PublicDate: 2008-09-18
3
 
References:
4
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4097
5
 
 https://usn.ubuntu.com/usn/usn-671-1
6
 
Description:
7
 
 MySQL 5.0.51a allows local users to bypass certain privilege checks by
8
 
 calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or
9
 
 (2) INDEX DIRECTORY arguments that are associated with symlinks within
10
 
 pathnames for subdirectories of the MySQL home data directory, which are
11
 
 followed when tables are created in the future. NOTE: this vulnerability
12
 
 exists because of an incomplete fix for CVE-2008-2079.
13
 
Ubuntu-Description:
14
 
Notes:
15
 
Bugs:
16
 
Priority: medium
17
 
Discovered-by:
18
 
Assigned-to: mdeslaur
19
 
 
20
 
Patches_mysql-dfsg-5.0:
21
 
upstream_mysql-dfsg-5.0: needs-triage
22
 
dapper_mysql-dfsg-5.0: released (5.0.22-0ubuntu6.06.11)
23
 
feisty_mysql-dfsg-5.0: needs-triage (reached end-of-life)
24
 
gutsy_mysql-dfsg-5.0: released (5.0.45-1ubuntu3.4)
25
 
hardy_mysql-dfsg-5.0: released (5.0.51a-3ubuntu5.4)
26
 
intrepid_mysql-dfsg-5.0: not-affected (5.0.67-0ubuntu6)
27
 
devel_mysql-dfsg-5.0: not-affected (5.0.67-0ubuntu6)