CVE-2005-0004
Summary
| CVE | CVE-2005-0004 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-04-14 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | The mysqlaccess script in MySQL 4.0.23 and earlier, 4.1.x before 4.1.10, 5.0.x before 5.0.3, and other versions including 3.x, allows local users to overwrite arbitrary files or read temporary files via a symlink attack on temporary files. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:L/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Home - Conectiva | af854a3a-2127-422b-91ae-364da2661108 | distro.conectiva.com.br | Third Party Advisory |
| MySQL Database MySQLAccess Local Insecure Temporary File Creation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch, Third Party Advisory, VDB Entry, Vendor Advisory |
| #101864: Multiple Security Vulnerabilities in The "MySQL" Package | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | Broken Link |
| marc.info | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Third Party Advisory |
| Advisories - Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | Broken Link |
| 404 Not Found | af854a3a-2127-422b-91ae-364da2661108 | mysql.osuosl.org | Broken Link |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| MySQL Lists: internals: bk commit into 4.0 tree (serg:1.2026) | af854a3a-2127-422b-91ae-364da2661108 | lists.mysql.com | Third Party Advisory |
| Secunia - Advisories - MySQL mysqlaccess Script Insecure Temporary File Creation | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Not Applicable |
| Debian -- Security Information -- DSA-647-1 mysql | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.