4.4
CVSSv2

CVE-2009-4030

Published: 30/11/2009 Updated: 07/11/2023
CVSS v2 Base Score: 4.4 | Impact Score: 6.4 | Exploitability Score: 3.4
VMScore: 392
Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

MySQL 5.1.x prior to 5.1.41 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL data home directory, related to incorrect calculation of the mysql_unpacked_real_data_home value. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4098 and CVE-2008-2079.

Vulnerable Product Search on Vulmon Subscribe to Product

mysql mysql 5.1.23

mysql mysql 5.1.32

mysql mysql 5.1.5

oracle mysql 5.1

oracle mysql 5.1.1

oracle mysql 5.1.2

oracle mysql 5.1.3

oracle mysql 5.1.4

oracle mysql 5.1.6

oracle mysql 5.1.7

oracle mysql 5.1.8

oracle mysql 5.1.9

oracle mysql 5.1.10

oracle mysql 5.1.11

oracle mysql 5.1.12

oracle mysql 5.1.13

oracle mysql 5.1.14

oracle mysql 5.1.15

oracle mysql 5.1.16

oracle mysql 5.1.17

oracle mysql 5.1.18

oracle mysql 5.1.19

oracle mysql 5.1.20

oracle mysql 5.1.21

oracle mysql 5.1.22

oracle mysql 5.1.30

Vendor Advisories

Synopsis Low: mysql security and bug fix update Type/Severity Security Advisory: Low Topic Updated mysql packages that fix one security issue and several bugs are nowavailable for Red Hat Enterprise Linux 5The Red Hat Security Response Team has rated this update as having lowsecurity impact A Common Vulne ...
Synopsis Moderate: mysql security update Type/Severity Security Advisory: Moderate Topic Updated mysql packages that fix multiple security issues are now availablefor Red Hat Enterprise Linux 5This update has been rated as having moderate security impact by the RedHat Security Response Team Descr ...
Synopsis Moderate: mysql security update Type/Severity Security Advisory: Moderate Topic Updated mysql packages that fix several security issues are now availablefor Red Hat Enterprise Linux 4This update has been rated as having moderate security impact by the RedHat Security Response Team Descri ...
Several vulnerabilities have been discovered in the MySQL database server The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-4019 Domas Mituzas discovered that mysqld does not properly handle errors during execution of certain SELECT statements with subqueries, and does not preserve certain null_value fla ...
It was discovered that MySQL could be made to overwrite existing table files in the data directory An authenticated user could use the DATA DIRECTORY and INDEX DIRECTORY options to possibly bypass privilege checks This update alters table creation behaviour by disallowing the use of the MySQL data directory in DATA DIRECTORY and INDEX DIRECTORY o ...