CVE-2008-4098
published 2008-09-18CVE-2008-4098: MySQL before 5.0.67 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2)…
PriorityP419medium4.6CVSS 2.0
AVNACHAuSCPIPAP
EPSS
1.62%
73.4th percentile
MySQL before 5.0.67 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL home data directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4097.
Affected
114 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| mysql | mysql | <= 5.1.45 | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:N/AC:H/Au:S/C:P/I:P/A:P
vendor_redhat4.6MEDIUM
vendor_ubuntu4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
MySQL vulnerabilities
vendor_ubuntu·2012-03-12
CVE-2007-5925 MySQL vulnerabilities
Title: MySQL vulnerabilities
Summary: Several security issues were fixed in MySQL.
Multiple security issues were discovered in MySQL and this update includes
new upstream MySQL versions to fix these issues.
MySQL has been updated to 5.1.61 in Ubuntu 10.04 LTS, Ubuntu 10.10,
Ubuntu 11.04 and Ubuntu 11.10. Ubuntu 8.04 LTS has been updated to
MySQL 5.0.95.
In addition to security fixes, the updated packages contain bug fixes, new
features, and possibly incompatible changes.
Please see the following for more information:
http://dev.mysql.com/doc/refman/5.1/en/news-5-1-x.html
http://dev.mysql.com/doc/refman/5.0/en/news-5-0-x.html
http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
MySQL vulnerabilities
vendor_ubuntu·2010-02-10·CVSS 4.6
CVE-2008-7247 [MEDIUM] MySQL vulnerabilities
Title: MySQL vulnerabilities
Summary: MySQL vulnerabilities
It was discovered that MySQL could be made to overwrite existing table
files in the data directory. An authenticated user could use the DATA
DIRECTORY and INDEX DIRECTORY options to possibly bypass privilege checks.
This update alters table creation behaviour by disallowing the use of the
MySQL data directory in DATA DIRECTORY and INDEX DIRECTORY options. This
issue only affected Ubuntu 8.10. (CVE-2008-4098)
It was discovered that MySQL contained a cross-site scripting vulnerability
in the command-line client when the --html option is enabled. An attacker
could place arbitrary web script or html in a database cell, which would
then get placed in the html document output by the command-line tool. This
issue only affected Ubuntu
Red Hat
mysql: Incomplete fix for CVE-2008-2079 / CVE-2008-4098
vendor_redhat·2009-11-04·CVSS 4.6
CVE-2009-4030 [MEDIUM] mysql: Incomplete fix for CVE-2008-2079 / CVE-2008-4098
mysql: Incomplete fix for CVE-2008-2079 / CVE-2008-4098
MySQL 5.1.x before 5.1.41 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL data home directory, related to incorrect calculation of the mysql_unpacked_real_data_home value. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4098 and CVE-2008-2079.
Red Hat
mysql: table destruction via DATA/INDEX DIRECTORY directives using symlinks
vendor_redhat·2008-11-22·CVSS 4.6
CVE-2010-1626 [MEDIUM] mysql: table destruction via DATA/INDEX DIRECTORY directives using symlinks
mysql: table destruction via DATA/INDEX DIRECTORY directives using symlinks
MySQL before 5.1.46 allows local users to delete the data and index files of another user's MyISAM table via a symlink attack in conjunction with the DROP TABLE command, a different vulnerability than CVE-2008-4098 and CVE-2008-7247.
Package: mysql (Red Hat Enterprise Linux 4) - Will not fix
Ubuntu
MySQL vulnerabilities
vendor_ubuntu·2008-11-17·CVSS 4.6
CVE-2008-2079 [MEDIUM] MySQL vulnerabilities
Title: MySQL vulnerabilities
Summary: MySQL vulnerabilities
It was discovered that MySQL could be made to overwrite existing table
files in the data directory. An authenticated user could use the
DATA DIRECTORY and INDEX DIRECTORY options to possibly bypass privilege
checks. This update alters table creation behaviour by disallowing the
use of the MySQL data directory in DATA DIRECTORY and INDEX DIRECTORY
options. (CVE-2008-2079, CVE-2008-4097 and CVE-2008-4098)
It was discovered that MySQL did not handle empty bit-string literals
properly. An attacker could exploit this problem and cause the MySQL
server to crash, leading to a denial of service. (CVE-2008-3963)
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
mysql: incomplete upstream fix for CVE-2008-2079
vendor_redhat·2008-07-03·CVSS 4.6
CVE-2008-4098 [MEDIUM] mysql: incomplete upstream fix for CVE-2008-2079
mysql: incomplete upstream fix for CVE-2008-2079
MySQL before 5.0.67 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL home data directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4097.
Statement: In Red Hat Enterprise Linux 5, issue CVE-2008-2079 was fixed without introducing CVE-2008-4098 in RHSA-2009:1289.
GHSA
GHSA-6c9m-2jhw-8335: MySQL before 5
ghsa_unreviewed·2022-05-13·CVSS 4.6
CVE-2010-1626 [MEDIUM] CWE-59 GHSA-6c9m-2jhw-8335: MySQL before 5
MySQL before 5.1.46 allows local users to delete the data and index files of another user's MyISAM table via a symlink attack in conjunction with the DROP TABLE command, a different vulnerability than CVE-2008-4098 and CVE-2008-7247.
GHSA
GHSA-q8q6-rcmj-g45q: MySQL 5
ghsa_unreviewed·2022-05-02·CVSS 4.6
CVE-2009-4030 [MEDIUM] CWE-59 GHSA-q8q6-rcmj-g45q: MySQL 5
MySQL 5.1.x before 5.1.41 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL data home directory, related to incorrect calculation of the mysql_unpacked_real_data_home value. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4098 and CVE-2008-2079.
GHSA
GHSA-cwr2-c5mc-rxv6: MySQL before 5
ghsa_unreviewed·2022-05-02·CVSS 4.6
CVE-2008-4098 [MEDIUM] CWE-59 GHSA-cwr2-c5mc-rxv6: MySQL before 5
MySQL before 5.0.67 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL home data directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4097.
No detection rules found.
Bugzilla
CVE-2010-1626 mysql: table destruction via DATA/INDEX DIRECTORY directives using symlinks
bugzilla·2010-01-08·CVSS 4.6
CVE-2010-1626 [MEDIUM] CVE-2010-1626 mysql: table destruction via DATA/INDEX DIRECTORY directives using symlinks
CVE-2010-1626 mysql: table destruction via DATA/INDEX DIRECTORY directives using symlinks
Ingo Strüwing reported another problem related to CVE-2008-2079 / CVE-2008-4098. A user with with privileges to CREATE / DROP tables in some MySQL database with shell access to the database server can remove data file for other tables using MyISAM storage engine, even in different databases.
Issue was first mentioned in upstream bug:
http://bugs.mysql.com/bug.php?id=39277
http://bugs.mysql.com/file.php?id=10707&text=1
Issue is tracked upstream via (previously public, but currently restricted) bug:
http://bugs.mysql.com/bug.php?id=40980
Problem has not upstream fix yet.
More details can be found in:
https://bugzilla.redhat.com/show_bug.cgi?id=543619#c4
Discussion:
Mitigation:
Disable use of tabl
Bugzilla
CVE-2008-7247 MySQL: Intended access restrictions bypass
bugzilla·2009-12-02·CVSS 6.0
CVE-2008-7247 [MEDIUM] CVE-2008-7247 MySQL: Intended access restrictions bypass
CVE-2008-7247 MySQL: Intended access restrictions bypass
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-7247 to
the following vulnerability:
sql/sql_table.cc in MySQL 5.0.x through 5.0.88, 5.1.x through 5.1.41,
and 6.0 before 6.0.9-alpha, when the data home directory contains a
symlink to a different filesystem, allows remote authenticated users
to bypass intended access restrictions by calling CREATE TABLE with a
(1) DATA DIRECTORY or (2) INDEX DIRECTORY argument referring to a
subdirectory that requires following this symlink.
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-7247
http://lists.mysql.com/commits/59711
http://marc.info/?l=oss-security&m=125908040022018&w=2
http://bugs.mysql.com/bug.php?id=39277
Upstream patch:
http://lists.mysql.c
Bugzilla
CVE-2009-4030 mysql: Incomplete fix for CVE-2008-2079 / CVE-2008-4098
bugzilla·2009-12-02·CVSS 4.6
CVE-2009-4030 [MEDIUM] CVE-2009-4030 mysql: Incomplete fix for CVE-2008-2079 / CVE-2008-4098
CVE-2009-4030 mysql: Incomplete fix for CVE-2008-2079 / CVE-2008-4098
Common Vulnerabilities and Exposures assigned an identifier CVE-2009-4030 to
the following vulnerability:
MySQL 5.1.x before 5.1.41 allows local users to bypass certain
privilege checks by calling CREATE TABLE on a MyISAM table with
modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are
originally associated with pathnames without symlinks, and that can
point to tables created at a future time at which a pathname is
modified to contain a symlink to a subdirectory of the MySQL data home
directory, related to incorrect calculation of the
mysql_unpacked_real_data_home value. NOTE: this vulnerability exists
because of an incomplete fix for CVE-2008-4098 and CVE-2008-2079.
References:
http://lists.mysql.com/
Bugzilla
CVE-2008-4098 mysql: incomplete upstream fix for CVE-2008-2079
bugzilla·2008-07-04·CVSS 4.6
CVE-2008-4098 [MEDIUM] CVE-2008-4098 mysql: incomplete upstream fix for CVE-2008-2079
CVE-2008-4098 mysql: incomplete upstream fix for CVE-2008-2079
Devin Carraway of the Debian Security Team discovered that the upstream fix for
the CVE-2008-2079 is incomplete and still makes it possible for local users to
create tables via INDEX/DATA DIRECTORY directives in the MySQL data directory
(/var/lib/mysql) via directory symlinks.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=480292#25
CVE-2008-2079 was tracked via bug bug #445222.
An attacker needs following to exploit this issue:
- MySQL database account with privileges to create tables
- shell access to the host running MySQL database with write access to a
directory accessible by the mysqld daemon process
Discussion:
Note: this attack does not work on existing tables. An attacker can only elevate
their access to anothe
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=480292#25http://bugs.mysql.com/bug.php?id=32167http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.htmlhttp://secunia.com/advisories/32578http://secunia.com/advisories/32759http://secunia.com/advisories/32769http://secunia.com/advisories/38517http://ubuntu.com/usn/usn-897-1http://www.debian.org/security/2008/dsa-1662http://www.mandriva.com/security/advisories?name=MDVSA-2009:094http://www.openwall.com/lists/oss-security/2008/09/09/20http://www.openwall.com/lists/oss-security/2008/09/16/3http://www.redhat.com/support/errata/RHSA-2009-1067.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0110.htmlhttp://www.ubuntu.com/usn/USN-1397-1http://www.ubuntu.com/usn/USN-671-1https://exchange.xforce.ibmcloud.com/vulnerabilities/45649https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10591http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=480292#25http://bugs.mysql.com/bug.php?id=32167http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.htmlhttp://secunia.com/advisories/32578http://secunia.com/advisories/32759http://secunia.com/advisories/32769http://secunia.com/advisories/38517http://ubuntu.com/usn/usn-897-1http://www.debian.org/security/2008/dsa-1662http://www.mandriva.com/security/advisories?name=MDVSA-2009:094http://www.openwall.com/lists/oss-security/2008/09/09/20http://www.openwall.com/lists/oss-security/2008/09/16/3http://www.redhat.com/support/errata/RHSA-2009-1067.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0110.htmlhttp://www.ubuntu.com/usn/USN-1397-1http://www.ubuntu.com/usn/USN-671-1https://exchange.xforce.ibmcloud.com/vulnerabilities/45649https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10591
2008-09-18
Published