Vulnerability Name: | CVE-2001-1275 (CCN-9996) |
Assigned: | 2001-01-17 |
Published: | 2001-01-17 |
Updated: | 2019-10-07 |
Summary: | MySQL before 3.23.31 allows users with a MySQL account to use the SHOW GRANTS command to obtain the encrypted administrator password from the mysql.user table and possibly gain privileges via password cracking.
|
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)Exploitability Metrics: | Attack Vector (AV): Local Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Changed
| Impact Metrics: | Confidentiality (C): High Integrity (I): High Availibility (A): High |
|
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)Exploitability Metrics: | Access Vector (AV): Local Access Complexity (AC): Low Authentication (Au): None | Impact Metrics: | Confidentiality (C): Complete Integrity (I): Complete Availibility (A): Complete | 7.2 High (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)Exploitability Metrics: | Access Vector (AV): Local Access Complexity (AC): Low Athentication (Au): None
| Impact Metrics: | Confidentiality (C): Complete Integrity (I): Complete Availibility (A): Complete |
|
Vulnerability Type: | CWE-Other
|
Vulnerability Consequences: | Obtain Information |
References: | Source: MITRE Type: CNA CVE-2001-1275
Source: FREEBSD Type: UNKNOWN FreeBSD-SA-01:16
Source: CCN Type: FreeBSD Security Advisory FreeBSD-SA-01:16 mysql may allow remote users to gain increased privileges
Source: CCN Type: RHSA-2001-003 Updated mysql packages available for Red Hat Linux 7
Source: CALDERA Type: UNKNOWN CSSA-2001-006.0
Source: MANDRAKE Type: UNKNOWN MDKSA-2001:014
Source: CCN Type: MySQL Web site MySQL Change History
Source: CCN Type: OSVDB ID: 8979 MySQL SHOW GRANTS Encrypted Password Disclosure
Source: REDHAT Type: Patch, Vendor Advisory RHSA-2001:003
Source: CCN Type: BID-2380 MySQL SHOW GRANTS Pasword Hash Disclosure Vulnerability
Source: CCN Type: MandrakeSoft Security Advisory MDKSA-2001:014 MySQL and php
Source: XF Type: UNKNOWN mysql-show-grants-password(9996)
|
Vulnerable Configuration: | Configuration 1: cpe:/a:oracle:mysql:*:*:*:*:*:*:*:* (Version <= 3.23.31) Configuration CCN 1: cpe:/a:oracle:mysql:3.23.8:*:*:*:*:*:*:*OR cpe:/a:mysql:mysql:3.23.20:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:3.23.10:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:3.23.11:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:3.23.12:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:3.23.13:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:3.23.14:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:3.23.15:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:3.23.16:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:3.23.17:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:3.23.18:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:3.23.19:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:3.23.2:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:3.23.20:beta:*:*:*:*:*:*OR cpe:/a:oracle:mysql:3.23.21:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:3.23.22:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:3.23.23:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:3.23.24:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:3.23.25:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:3.23.26:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:3.23.27:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:3.23.28:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:3.23.28:gamma:*:*:*:*:*:*OR cpe:/a:oracle:mysql:3.23.29:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:3.23.3:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:3.23.30:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:3.23.4:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:3.23.5:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:3.23.6:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:3.23.7:*:*:*:*:*:*:*OR cpe:/a:oracle:mysql:3.23.9:*:*:*:*:*:*:*AND cpe:/o:redhat:linux:7:*:*:*:*:*:*:*OR cpe:/o:mandrakesoft:mandrake_linux:7.2:*:*:*:*:*:*:*OR cpe:/o:redhat:linux:7.1:*:*:*:*:*:*:*OR cpe:/o:redhat:linux:7.2:*:*:*:*:*:*:*OR cpe:/o:redhat:linux:7.3:*:*:*:*:*:*:*
Denotes that component is vulnerable |
BACK |