MySQL MyISAM Table Privileges Secuity Bypass Vulnerability

MySQL is prone to a security-bypass vulnerability.

An attacker can exploit this issue to gain access to table files created by other users, bypassing certain security restrictions.

NOTE 1: This issue was also assigned CVE-2008-4097 because CVE-2008-2079 was incompletely fixed, allowing symlink attacks.

NOTE 2: CVE-2008-4098 was assigned because fixes for the vector described in CVE-2008-4097 can also be bypassed.

This issue affects versions prior to MySQL 4 (prior to 4.1.24) and MySQL 5 (prior to 5.0.60).


 

Privacy Statement
Copyright 2010, SecurityFocus