Oval Definition:oval:org.mitre.oval:def:7628
Revision Date:2014-06-23Version:17
Title:DSA-1662 mysql-dfsg-5.0 -- authorisation bypass
Description:A symlink traversal vulnerability was discovered in MySQL, a relational database server. The weakness could permit an attacker having both CREATE TABLE access to a database and the ability to execute shell commands on the database server to bypass MySQL access controls, enabling them to write to tables in databases to which they would not ordinarily have access. The Common Vulnerabilities and Exposures project identifies this vulnerability as CVE-2008-4098. Note that a closely aligned issue, identified as CVE-2008-4097, was prevented by the update announced in DSA-1608-1. This new update supersedes that fix and mitigates both potential attack vectors.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2008-4097
CVE-2008-4098
DSA-1662
Platform(s):Debian GNU/Linux 4.0
Product(s):mysql-dfsg-5.0
Definition Synopsis
  • Debian GNU/Linux 4.0 is installed.
  • AND Architecture section
  • Architecture independent section
  • Installed architecture is all
  • AND Packages section
  • mysql-client is earlier than 5.0.32-7etch8
  • OR mysql-common is earlier than 5.0.32-7etch8
  • OR mysql-server is earlier than 5.0.32-7etch8
  • OR libmysqlclient15-dev is earlier than 5.0.32-7etch8
  • OR mysql-server-4.1 is earlier than 5.0.32-7etch8
  • OR mysql-client-5.0 is earlier than 5.0.32-7etch8
  • OR mysql-server-5.0 is earlier than 5.0.32-7etch8
  • OR libmysqlclient15off is earlier than 5.0.32-7etch8
  • BACK