The mysqlaccess script in MySQL 4.0.23 and earlier, 4.1.x before 4.1.10, 5.0.x before 5.0.3, and other versions including 3.x, allows local users to overwrite arbitrary files or read temporary files via a symlink attack on temporary files.
2005-04-14T04:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 4.6 (MEDIUM)
AV:L/AC:L/Au:N/C:P/I:P/A:P
3.9
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | oracle | mysql | < 4.0.23 | Yes |
Application | oracle | mysql | < 4.1.10 | Yes |
Application | oracle | mysql | < 5.0.3 | Yes |
Operating System | debian | debian_linux | 3.0 | Yes |
Application | mariadb | mariadb | < 5.5.66 | Yes |