Oval Definition:oval:org.mitre.oval:def:20470
Revision Date:2014-02-17Version:11
Title:RHSA-2013:0121: mysql security and bug fix update (Low)
Description:MySQL 5.0.88, and possibly other versions and platforms, allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL data home directory, related to incorrect calculation of the mysql_unpacked_real_data_home value. NOTE: this vulnerability exists because of a CVE-2009-4030 regression, which was not omitted in other packages and versions such as MySQL 5.0.95 in Red Hat Enterprise Linux 6.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CESA-2013:0121
CVE-2012-4452
RHSA-2013:0121-00
Platform(s):CentOS Linux 5
Red Hat Enterprise Linux 5
Product(s):mysql
Definition Synopsis
  • Redhat 5 or Centos 5 release
  • The operating system installed on the system is Red Hat Enterprise Linux 5
  • OR The operating system installed on the system is CentOS Linux 5.x
  • AND Packages section
  • mysql-server is earlier than 0:5.0.95-3.el5
  • OR mysql-bench is earlier than 0:5.0.95-3.el5
  • OR mysql is earlier than 0:5.0.95-3.el5
  • OR mysql-devel is earlier than 0:5.0.95-3.el5
  • OR mysql-test is earlier than 0:5.0.95-3.el5
  • BACK