// For flags

CVE-2008-4098

mysql: incomplete upstream fix for CVE-2008-2079

Severity Score

4.6
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

MySQL before 5.0.67 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL home data directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4097.

MySQL anterior a 5.0.67, permite a usuarios locales evitar determinadas comprobaciones de privilegios haciendo una llamada CREATE TABLE en una tabla MyISAM que modifica los argumentos (1) DATA DIRECTORY o (2) INDEX DIRECTORY que están asociados originalmente con los nombres de ruta (pathname) sin enlaces simbólicos, y que pueden apuntar a tablas creadas después de que un nombre de ruta sea modificado para tener un enlace simbólico a un subdirectorio del directorio de datos inicial de MySQL. NOTA: esta vulnerabilidad es debida a que no se solucionó completamente la vulnerabilidad CVE-2008-4097.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
Partial
Attack Vector
Local
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-09-15 CVE Reserved
  • 2008-09-17 CVE Published
  • 2024-07-14 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-59: Improper Link Resolution Before File Access ('Link Following')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Canonical
Search vendor "Canonical"
Ubuntu Linux
Search vendor "Canonical" for product "Ubuntu Linux"
6.06
Search vendor "Canonical" for product "Ubuntu Linux" and version "6.06"
lts
Affected
Canonical
Search vendor "Canonical"
Ubuntu Linux
Search vendor "Canonical" for product "Ubuntu Linux"
7.10
Search vendor "Canonical" for product "Ubuntu Linux" and version "7.10"
-
Affected
Canonical
Search vendor "Canonical"
Ubuntu Linux
Search vendor "Canonical" for product "Ubuntu Linux"
8.04
Search vendor "Canonical" for product "Ubuntu Linux" and version "8.04"
lts
Affected
Canonical
Search vendor "Canonical"
Ubuntu Linux
Search vendor "Canonical" for product "Ubuntu Linux"
8.10
Search vendor "Canonical" for product "Ubuntu Linux" and version "8.10"
-
Affected
Canonical
Search vendor "Canonical"
Ubuntu Linux
Search vendor "Canonical" for product "Ubuntu Linux"
9.04
Search vendor "Canonical" for product "Ubuntu Linux" and version "9.04"
-
Affected
Canonical
Search vendor "Canonical"
Ubuntu Linux
Search vendor "Canonical" for product "Ubuntu Linux"
9.10
Search vendor "Canonical" for product "Ubuntu Linux" and version "9.10"
-
Affected
Debian
Search vendor "Debian"
Debian Linux
Search vendor "Debian" for product "Debian Linux"
5.0
Search vendor "Debian" for product "Debian Linux" and version "5.0"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.0
Search vendor "Mysql" for product "Mysql" and version "5.0.0"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.1
Search vendor "Mysql" for product "Mysql" and version "5.0.1"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.2
Search vendor "Mysql" for product "Mysql" and version "5.0.2"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.3
Search vendor "Mysql" for product "Mysql" and version "5.0.3"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.4
Search vendor "Mysql" for product "Mysql" and version "5.0.4"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.5
Search vendor "Mysql" for product "Mysql" and version "5.0.5"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.10
Search vendor "Mysql" for product "Mysql" and version "5.0.10"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.15
Search vendor "Mysql" for product "Mysql" and version "5.0.15"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.16
Search vendor "Mysql" for product "Mysql" and version "5.0.16"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.17
Search vendor "Mysql" for product "Mysql" and version "5.0.17"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.20
Search vendor "Mysql" for product "Mysql" and version "5.0.20"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.24
Search vendor "Mysql" for product "Mysql" and version "5.0.24"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.30
Search vendor "Mysql" for product "Mysql" and version "5.0.30"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.36
Search vendor "Mysql" for product "Mysql" and version "5.0.36"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.44
Search vendor "Mysql" for product "Mysql" and version "5.0.44"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.54
Search vendor "Mysql" for product "Mysql" and version "5.0.54"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.56
Search vendor "Mysql" for product "Mysql" and version "5.0.56"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.60
Search vendor "Mysql" for product "Mysql" and version "5.0.60"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.66
Search vendor "Mysql" for product "Mysql" and version "5.0.66"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.23
Search vendor "Oracle" for product "Mysql" and version "5.0.23"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.25
Search vendor "Oracle" for product "Mysql" and version "5.0.25"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.26
Search vendor "Oracle" for product "Mysql" and version "5.0.26"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.28
Search vendor "Oracle" for product "Mysql" and version "5.0.28"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.30
Search vendor "Oracle" for product "Mysql" and version "5.0.30"
sp1
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.32
Search vendor "Oracle" for product "Mysql" and version "5.0.32"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.34
Search vendor "Oracle" for product "Mysql" and version "5.0.34"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.36
Search vendor "Oracle" for product "Mysql" and version "5.0.36"
sp1
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.38
Search vendor "Oracle" for product "Mysql" and version "5.0.38"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.40
Search vendor "Oracle" for product "Mysql" and version "5.0.40"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.41
Search vendor "Oracle" for product "Mysql" and version "5.0.41"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.42
Search vendor "Oracle" for product "Mysql" and version "5.0.42"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.44
Search vendor "Oracle" for product "Mysql" and version "5.0.44"
sp1
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.45
Search vendor "Oracle" for product "Mysql" and version "5.0.45"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.46
Search vendor "Oracle" for product "Mysql" and version "5.0.46"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.48
Search vendor "Oracle" for product "Mysql" and version "5.0.48"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.50
Search vendor "Oracle" for product "Mysql" and version "5.0.50"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.50
Search vendor "Oracle" for product "Mysql" and version "5.0.50"
sp1
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.51
Search vendor "Oracle" for product "Mysql" and version "5.0.51"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.52
Search vendor "Oracle" for product "Mysql" and version "5.0.52"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.56
Search vendor "Oracle" for product "Mysql" and version "5.0.56"
sp1
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.58
Search vendor "Oracle" for product "Mysql" and version "5.0.58"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.60
Search vendor "Oracle" for product "Mysql" and version "5.0.60"
sp1
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.62
Search vendor "Oracle" for product "Mysql" and version "5.0.62"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.64
Search vendor "Oracle" for product "Mysql" and version "5.0.64"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.66
Search vendor "Oracle" for product "Mysql" and version "5.0.66"
sp1
Affected