6
CVSSv2

CVE-2008-7247

Published: 30/11/2009 Updated: 17/12/2019
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
VMScore: 536
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

sql/sql_table.cc in MySQL 5.0.x up to and including 5.0.88, 5.1.x up to and including 5.1.41, and 6.0 prior to 6.0.9-alpha, when the data home directory contains a symlink to a different filesystem, allows remote authenticated users to bypass intended access restrictions by calling CREATE TABLE with a (1) DATA DIRECTORY or (2) INDEX DIRECTORY argument referring to a subdirectory that requires following this symlink.

Vulnerable Product Search on Vulmon Subscribe to Product

mysql mysql 5.0.20

mysql mysql 5.0.2

mysql mysql 5.0.16

oracle mysql 5.0.0

oracle mysql 5.0.11

mysql mysql 5.0.1

oracle mysql 5.0.42

mysql mysql 5.0.56

oracle mysql 5.0.51

mysql mysql 5.0.5.0.21

oracle mysql 5.0.33

mysql mysql 5.0.4

oracle mysql 5.0.7

oracle mysql 5.0.75

mysql mysql 5.1.5

oracle mysql 5.1.6

oracle mysql 5.1.14

oracle mysql 5.1.11

oracle mysql 5.1

oracle mysql 5.1.10

oracle mysql 5.1.19

oracle mysql 5.1.20

mysql mysql 5.0.17

mysql mysql 5.0.0

oracle mysql 5.0.14

mysql mysql 5.0.10

oracle mysql 5.0.30

mysql mysql 5.0.54

oracle mysql 5.0.52

mysql mysql 5.0.5

oracle mysql 5.0.6

oracle mysql 5.0.77

oracle mysql 5.0.8

oracle mysql 5.1.3

oracle mysql 5.1.4

oracle mysql 5.1.12

oracle mysql 5.1.17

oracle mysql 5.1.1

mysql mysql 5.1.32

oracle mysql 6.0.2

oracle mysql 6.0.1

oracle mysql 5.0.21

oracle mysql 5.0.22

oracle mysql 5.0.18

mysql mysql 5.0.15

oracle mysql 5.0.12

oracle mysql 5.0.50

oracle mysql 5.0.45

oracle mysql 5.0.38

oracle mysql 5.0.3

mysql mysql 5.0.3

oracle mysql 5.0.41

oracle mysql 5.0.27

oracle mysql 5.0.81

mysql mysql 5.0.82

oracle mysql 5.1.9

oracle mysql 5.1.7

oracle mysql 5.1.2

oracle mysql 5.1.15

oracle mysql 5.1.21

oracle mysql 5.1.22

mysql mysql 5.1.23

oracle mysql 6.0.4

oracle mysql 6.0.3

oracle mysql 5.0.23

oracle mysql 5.0.25

mysql mysql 5.0.22.1.0.1

mysql mysql 5.0.24

oracle mysql 5.0.19

oracle mysql 5.0.13

mysql mysql 5.0.44

mysql mysql 5.0.30

mysql mysql 5.0.36

oracle mysql 5.0.32

oracle mysql 5.0.37

oracle mysql 5.0.26

mysql mysql 5.0.60

mysql mysql 5.0.66

oracle mysql 5.0.83

oracle mysql 5.1.8

oracle mysql 5.1.13

oracle mysql 5.1.16

oracle mysql 5.1.30

oracle mysql 5.1.18

oracle mysql 6.0.0

mysql mysql 6.0.9

Vendor Advisories

It was discovered that MySQL could be made to overwrite existing table files in the data directory An authenticated user could use the DATA DIRECTORY and INDEX DIRECTORY options to possibly bypass privilege checks This update alters table creation behaviour by disallowing the use of the MySQL data directory in DATA DIRECTORY and INDEX DIRECTORY o ...