CVE-2008-7247Link Following in Mysql

CWE-59Link Following9 documents5 sources
Severity
6.0MEDIUMNVD
NVD3.6
EPSS
0.2%
top 52.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 30
Latest updateMay 13

Description

sql/sql_table.cc in MySQL 5.0.x through 5.0.88, 5.1.x through 5.1.41, and 6.0 before 6.0.9-alpha, when the data home directory contains a symlink to a different filesystem, allows remote authenticated users to bypass intended access restrictions by calling CREATE TABLE with a (1) DATA DIRECTORY or (2) INDEX DIRECTORY argument referring to a subdirectory that requires following this symlink.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 6.8 | Impact: 6.4

Affected Packages2 packages

NVDmysql/mysql5.1.45+32
NVDoracle/mysql77 versions+76

🔴Vulnerability Details

2
GHSA
GHSA-3qjw-qphv-c728: sql/sql_table2022-05-13
GHSA
GHSA-6c9m-2jhw-8335: MySQL before 52022-05-13

📋Vendor Advisories

4
Ubuntu
MySQL vulnerabilities2012-03-12
Ubuntu
MySQL vulnerabilities2010-02-10
Red Hat
MySQL: Intended access restrictions bypass2009-11-04
Red Hat
mysql: table destruction via DATA/INDEX DIRECTORY directives using symlinks2008-11-22

💬Community

1
Bugzilla
CVE-2008-7247 MySQL: Intended access restrictions bypass2009-12-02
CVE-2008-7247 — Link Following in Mysql | cvebase