CVE-2013-2162
published 2013-08-19CVE-2013-2162: Race condition in the post-installation script (mysql-server-5.5.postinst) for MySQL Server 5.5 for Debian GNU/Linux and Ubuntu Linux creates a configuration…
PriorityP45low1.9CVSS 2.0
AVLACMAuNCPINAN
EPSS
0.35%
27.6th percentile
Race condition in the post-installation script (mysql-server-5.5.postinst) for MySQL Server 5.5 for Debian GNU/Linux and Ubuntu Linux creates a configuration file with world-readable permissions before restricting the permissions, which allows local users to read the file and obtain sensitive information such as credentials.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c7v5-6xxq-xfvw: Race condition in the post-installation script (mysql-server-5
ghsa_unreviewed·2022-05-17
CVE-2013-2162 [LOW] CWE-362 GHSA-c7v5-6xxq-xfvw: Race condition in the post-installation script (mysql-server-5
Race condition in the post-installation script (mysql-server-5.5.postinst) for MySQL Server 5.5 for Debian GNU/Linux and Ubuntu Linux creates a configuration file with world-readable permissions before restricting the permissions, which allows local users to read the file and obtain sensitive information such as credentials.
Ubuntu
MySQL vulnerabilities
vendor_ubuntu·2013-07-25
CVE-2013-1861 MySQL vulnerabilities
Title: MySQL vulnerabilities
Summary: Several security issues were fixed in MySQL.
Multiple security issues were discovered in MySQL and this update includes
new upstream MySQL versions to fix these issues.
MySQL has been updated to 5.1.70 in Ubuntu 10.04 LTS. Ubuntu 12.04 LTS,
Ubuntu 12.10 and Ubuntu 13.04 have been updated to MySQL 5.5.32.
In addition to security fixes, the updated packages contain bug fixes,
new features, and possibly incompatible changes.
Please see the following for more information:
http://dev.mysql.com/doc/relnotes/mysql/5.1/en/news-5-1-70.html
http://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-32.html
http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html
Instructions: In general, a standard system update will make all the necessary c
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=711600http://seclists.org/oss-sec/2013/q2/528http://secunia.com/advisories/54300http://ubuntu.com/usn/usn-1909-1http://www.debian.org/security/2013/dsa-2818http://www.securityfocus.com/bid/60424http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=711600http://seclists.org/oss-sec/2013/q2/528http://secunia.com/advisories/54300http://ubuntu.com/usn/usn-1909-1http://www.debian.org/security/2013/dsa-2818http://www.securityfocus.com/bid/60424
2013-08-19
Published