CVE-2008-4098Link Following in Mysql

CWE-59Link Following17 documents6 sources
Severity
4.6MEDIUMNVD
NVD4.4NVD3.6
EPSS
0.3%
top 42.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 18
Latest updateMay 13

Description

MySQL before 5.0.67 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL home data directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4097.

CVSS vector

AV:N/AC:H/C:P/I:P/A:PExploitability: 3.9 | Impact: 6.4

Affected Packages2 packages

NVDmysql/mysql5.1.45+30
NVDoracle/mysql76 versions+75

Also affects: Debian Linux 5.0, Ubuntu Linux 6.06, 7.10, 8.04, 8.10, 9.04, 9.10

Patches

🔴Vulnerability Details

3
GHSA
GHSA-6c9m-2jhw-8335: MySQL before 52022-05-13
GHSA
GHSA-q8q6-rcmj-g45q: MySQL 52022-05-02
GHSA
GHSA-cwr2-c5mc-rxv6: MySQL before 52022-05-02

💥Exploits & PoCs

1
Exploit-DB
freeSSHd 1.2.1 - (Authenticated) Remote Stack Overflow (PoC)2008-05-31

📋Vendor Advisories

6
Ubuntu
MySQL vulnerabilities2012-03-12
Ubuntu
MySQL vulnerabilities2010-02-10
Red Hat
mysql: Incomplete fix for CVE-2008-2079 / CVE-2008-40982009-11-04
Red Hat
mysql: table destruction via DATA/INDEX DIRECTORY directives using symlinks2008-11-22
Ubuntu
MySQL vulnerabilities2008-11-17

💬Community

4
Bugzilla
CVE-2010-1626 mysql: table destruction via DATA/INDEX DIRECTORY directives using symlinks2010-01-08
Bugzilla
CVE-2008-7247 MySQL: Intended access restrictions bypass2009-12-02
Bugzilla
CVE-2009-4030 mysql: Incomplete fix for CVE-2008-2079 / CVE-2008-40982009-12-02
Bugzilla
CVE-2008-4098 mysql: incomplete upstream fix for CVE-2008-20792008-07-04
CVE-2008-4098 — Link Following in Mysql | cvebase