cbcvebase.
CVE-2008-4098
published 2008-09-18

CVE-2008-4098: MySQL before 5.0.67 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2)…

PriorityP419medium4.6CVSS 2.0
AVNACHAuSCPIPAP
EPSS
1.62%
73.4th percentile
MySQL before 5.0.67 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL home data directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4097.

Affected

114 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
mysqlmysql<= 5.1.45
mysqlmysql
mysqlmysql
mysqlmysql
mysqlmysql
mysqlmysql
mysqlmysql
mysqlmysql
mysqlmysql
mysqlmysql
mysqlmysql
mysqlmysql
mysqlmysql
mysqlmysql
mysqlmysql
mysqlmysql
mysqlmysql
mysqlmysql

CVSS provenance

nvdv2.04.6MEDIUMAV:N/AC:H/Au:S/C:P/I:P/A:P
vendor_redhat4.6MEDIUM
vendor_ubuntu4.6MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.