CVE-2004-0957

7 documents6 sources
Severity
6.8MEDIUM
EPSS
0.5%
top 34.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 9
Latest updateApr 29

Description

Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database whose name includes a "_" (underscore), grants privileges to other databases that have similar names, which can allow the user to conduct unauthorized activities.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages5 packages

NVDoracle/mysql75 versions+74
NVDopenpkg/openpkg2.1, 2.2, current+2
NVDsuse/suse_linux6 versions+5
NVDtrustix/secure_linux1.5, 2.0, 2.1+2

Also affects: Ubuntu Linux 4.1, Enterprise Linux 3.0

🔴Vulnerability Details

2
GHSA
GHSA-hx63-8p37-c3fh: Unknown vulnerability in MySQL 32022-04-29
CVEList
CVE-2004-0957: Unknown vulnerability in MySQL 32004-10-21

📋Vendor Advisories

3
Ubuntu
MySQL vulnerability2005-04-06
Ubuntu
mysql vulnerabilities2004-11-25
Red Hat
security flaw2004-05-29

💬Community

1
Bugzilla
CVE-2004-0957 security flaw2018-08-16