← Back

CVE-2008-4098

nvd nist
Published: Sep 18, 2008Modified: Apr 23, 2026

JSON object

Loading...
4.6
Vector
AV:N/AC:H/Au:S/C:P/I:P/A:P
Exploitability: 3.9 / Impact: 6.4
Source: NVD

Description

MySQL before 5.0.67 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL home data directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4097.

Affected (52)

Products: Canonical: Ubuntu Linux · Debian: Debian Linux · Mysql: Mysql · +1 more
Show all products
1 product
Ubuntu Linux
1 product
Debian Linux
1 product
Mysql
1 product
Mysql
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 6.06
Version 7.10
Version 8.04
Version 8.10
Version 9.04
Version 9.10
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 5.0
Configuration C
45 vulnerable
Vulnerable SoftwareAffected Versions
Mysql
Version 5.0.0
Version 5.0.10
Version 5.0.15
Version 5.0.16
Version 5.0.17
Version 5.0.1
Version 5.0.20
Version 5.0.24
Version 5.0.2
Version 5.0.30
Version 5.0.36
Version 5.0.3
Version 5.0.44
Version 5.0.4
Version 5.0.54
Version 5.0.56
Version 5.0.5
Version 5.0.60
Version 5.0.66
Oracle
Version 5.0.23
Version 5.0.25
Version 5.0.26
Version 5.0.28
Version 5.0.30 sp1
Version 5.0.32
Version 5.0.34
Version 5.0.36 sp1
Version 5.0.38
Version 5.0.40
Version 5.0.41
Version 5.0.42
Version 5.0.44 sp1
Version 5.0.45
Version 5.0.46
Version 5.0.48
Version 5.0.50
Version 5.0.50 sp1
Version 5.0.51
Version 5.0.52
Version 5.0.56 sp1
Version 5.0.58
Version 5.0.60 sp1
Version 5.0.62
Version 5.0.64
Version 5.0.66 sp1

References (36)

Source: secalert@redhat.com
Issue TrackingThird Party Advisory
Source: secalert@redhat.com
Issue TrackingPatchVendor Advisory
Source: secalert@redhat.com
Not Applicable
Source: secalert@redhat.com
Not Applicable
Source: secalert@redhat.com
Not Applicable
Source: secalert@redhat.com
Not Applicable
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Mailing ListThird Party Advisory
Source: secalert@redhat.com
Mailing ListThird Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Source: secalert@redhat.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.