CVE-2005-0004
published 2005-04-14CVE-2005-0004: The mysqlaccess script in MySQL 4.0.23 and earlier, 4.1.x before 4.1.10, 5.0.x before 5.0.3, and other versions including 3.x, allows local users to overwrite…
PriorityP414medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.59%
44.5th percentile
The mysqlaccess script in MySQL 4.0.23 and earlier, 4.1.x before 4.1.10, 5.0.x before 5.0.3, and other versions including 3.x, allows local users to overwrite arbitrary files or read temporary files via a symlink attack on temporary files.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| mariadb | mariadb | >= 5.5.0 < 5.5.66 | 5.5.66 |
| oracle | mysql | >= 4.0.0 < 4.0.23 | 4.0.23 |
| oracle | mysql | >= 4.1.0 < 4.1.10 | 4.1.10 |
| oracle | mysql | >= 5.0.0 < 5.0.3 | 5.0.3 |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7f63-6j3v-p9vw: The mysqlaccess script in MySQL 4
ghsa_unreviewed·2022-05-01
CVE-2005-0004 [MEDIUM] CWE-59 GHSA-7f63-6j3v-p9vw: The mysqlaccess script in MySQL 4
The mysqlaccess script in MySQL 4.0.23 and earlier, 4.1.x before 4.1.10, 5.0.x before 5.0.3, and other versions including 3.x, allows local users to overwrite arbitrary files or read temporary files via a symlink attack on temporary files.
Red Hat
mysql: mysqlaccess creates/overwrite files on the system
vendor_redhat·2005-01-19·CVSS 4.6
CVE-2005-0004 [MEDIUM] CWE-266 mysql: mysqlaccess creates/overwrite files on the system
mysql: mysqlaccess creates/overwrite files on the system
The mysqlaccess script in MySQL 4.0.23 and earlier, 4.1.x before 4.1.10, 5.0.x before 5.0.3, and other versions including 3.x, allows local users to overwrite arbitrary files or read temporary files via a symlink attack on temporary files.
Package: mysql55-mysql (Red Hat Enterprise Linux 5) - Not affected
Package: mysql (Red Hat Enterprise Linux 6) - Not affected
Package: mariadb (Red Hat Enterprise Linux 7) - Not affected
Package: mariadb-galera (Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)) - Not affected
Package: mariadb-galera (Red Hat Enterprise Linux OpenStack Platform 6 (Juno)) - Not affected
Package: mariadb-galera (Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)) - Not affected
Package: mariadb-galer
Ubuntu
MySQL client vulnerability
vendor_ubuntu·2005-01-19
CVE-2005-0004 MySQL client vulnerability
Title: MySQL client vulnerability
Summary: MySQL client vulnerability
Javier Fernández-Sanguino Peña noticed that the "mysqlaccess" program
created temporary files in an insecure manner. This could allow a
symbolic link attack to create or overwrite arbitrary files with the
privileges of the user invoking the program.
Instructions: In general, a standard system update will make all the necessary changes.
No detection rules found.
No public exploits indexed.
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000947http://lists.mysql.com/internals/20600http://marc.info/?l=bugtraq&m=110608297217224&w=2http://mysql.osuosl.org/doc/mysql/en/News-4.1.10.htmlhttp://secunia.com/advisories/13867http://sunsolve.sun.com/search/document.do?assetkey=1-26-101864-1http://www.debian.org/security/2005/dsa-647http://www.mandriva.com/security/advisories?name=MDKSA-2005:036http://www.securityfocus.com/bid/12277https://exchange.xforce.ibmcloud.com/vulnerabilities/18922http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000947http://lists.mysql.com/internals/20600http://marc.info/?l=bugtraq&m=110608297217224&w=2http://mysql.osuosl.org/doc/mysql/en/News-4.1.10.htmlhttp://secunia.com/advisories/13867http://sunsolve.sun.com/search/document.do?assetkey=1-26-101864-1http://www.debian.org/security/2005/dsa-647http://www.mandriva.com/security/advisories?name=MDKSA-2005:036http://www.securityfocus.com/bid/12277https://exchange.xforce.ibmcloud.com/vulnerabilities/18922
2005-04-14
Published