{"api_version":"1","generated_at":"2026-07-23T07:09:21+00:00","cve":"CVE-2008-2079","urls":{"html":"https://cve.report/CVE-2008-2079","api":"https://cve.report/api/cve/CVE-2008-2079.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-2079","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-2079"},"summary":{"title":"CVE-2008-2079","description":"MySQL 4.1.x before 4.1.24, 5.0.x before 5.0.60, 5.1.x before 5.1.24, and 6.0.x before 6.0.5 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are within the MySQL home data directory, which can point to tables that are created in the future.","state":"PUBLISHED","assigner":"redhat","published_at":"2008-05-05 16:20:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.6","severity":"","vector":"AV:N/AC:H/Au:S/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:H/Au:S/C:P/I:P/A:P","baseScore":4.6,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://dev.mysql.com/doc/refman/4.1/en/news-4-1-24.html","name":"http://dev.mysql.com/doc/refman/4.1/en/news-4-1-24.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"MySQL ::   MySQL 3.23, 4.0, 4.1 Reference Manual :: B.1.2 Changes in  MySQL 4.1.24 (01 March 2008)","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/42267","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/42267","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/32222","name":"http://secunia.com/advisories/32222","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Apple Mac OS X Security Update Fixes Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2008/dsa-1608","name":"http://www.debian.org/security/2008/dsa-1608","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Debian -- Security Information -- DSA-1608-1 mysql-dfsg-5.0","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://bugs.mysql.com/bug.php?id=32167","name":"http://bugs.mysql.com/bug.php?id=32167","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch","Vendor Advisory"],"title":"MySQL Bugs: #32167: another privilege bypass with DATA/INDEX DIRECTORY","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2008-0768.html","name":"http://www.redhat.com/support/errata/RHSA-2008-0768.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"rhn.redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/31687","name":"http://secunia.com/advisories/31687","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"SUSE Update for Multiple Packages - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/36566","name":"http://secunia.com/advisories/36566","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Red Hat update for mysql - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.html","name":"http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"[security-announce] SUSE Security Summary Report SUSE-SR:2008:017","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2008/2780","name":"http://www.vupen.com/english/advisories/2008/2780","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://dev.mysql.com/doc/refman/5.1/en/news-5-1-24.html","name":"http://dev.mysql.com/doc/refman/5.1/en/news-5-1-24.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"MySQL ::   MySQL 5.1 Reference Manual :: C.1.8 Changes in  MySQL 5.1.24 (08 April 2008)","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/29106","name":"http://www.securityfocus.com/bid/29106","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory","VDB Entry"],"title":"MySQL MyISAM Table Privileges Secuity Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/31066","name":"http://secunia.com/advisories/31066","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Debian update for mysql-dfsg-5.0  - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/36701","name":"http://secunia.com/advisories/36701","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Apple Mac OS X Security Update Fixes Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://dev.mysql.com/doc/refman/5.0/en/releasenotes-es-5-0-60.html","name":"http://dev.mysql.com/doc/refman/5.0/en/releasenotes-es-5-0-60.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"MySQL ::   MySQL 5.0 Reference Manual :: C.1.11 Release Notes for  MySQL Enterprise 5.0.60 [MRU] (28 April 2008)","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://dev.mysql.com/doc/refman/6.0/en/news-6-0-5.html","name":"http://dev.mysql.com/doc/refman/6.0/en/news-6-0-5.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"MySQL ::   MySQL 6.0 Reference Manual :: C.1.5 Changes in  MySQL 6.0.5 (12 June 2008)","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://support.apple.com/kb/HT3216","name":"http://support.apple.com/kb/HT3216","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"About Security Update 2008-007","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/30134","name":"http://secunia.com/advisories/30134","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"MySQL MyISAM Table Privilege Check Bypass - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:149","name":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:149","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Advisories | Mandriva","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ubuntu.com/usn/USN-671-1","name":"http://www.ubuntu.com/usn/USN-671-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"USN-671-1: MySQL vulnerabilities | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10133","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10133","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2008/1472/references","name":"http://www.vupen.com/english/advisories/2008/1472/references","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Webmail - OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2009-1289.html","name":"http://www.redhat.com/support/errata/RHSA-2009-1289.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/31226","name":"http://secunia.com/advisories/31226","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Red Hat update for mysql - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1019995","name":"http://www.securitytracker.com/id?1019995","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"SecurityTracker.com Archives - MySQL MyISAM Options Let Local Users Overwrite Table Files","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/32769","name":"http://secunia.com/advisories/32769","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Ubuntu update for mysql-dfsg-5.0 - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html","name":"http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"APPLE-SA-2008-10-09 Security Update 2008-007","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://support.apple.com/kb/HT3865","name":"http://support.apple.com/kb/HT3865","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"About Security Update 2009-005","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html","name":"http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"APPLE-SA-2009-09-10-2 Security Update 2009-005","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/31681","name":"http://www.securityfocus.com/bid/31681","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory","VDB Entry"],"title":"RETIRED: Apple Mac OS X 2008-007 Multiple Security Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:150","name":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:150","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Advisories | Mandriva","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2008-0505.html","name":"http://www.redhat.com/support/errata/RHSA-2008-0505.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"rhn.redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2008-0510.html","name":"http://www.redhat.com/support/errata/RHSA-2008-0510.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"rhn.redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-2079","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-2079","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"2079","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mysql","cpe5":"mysql","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[{"cvename":"CVE-2008-2079","organization":"Red Hat","lastmodified":"2009-09-02","contributor":"Tomas Hoger","statementText":"This issue did not affect MySQL as supplied with Red Hat Enterprise Linux 3. This issue was addressed for Red Hat Enterprise Linux 4, 5, and Red Hat Application Stack v1, v2: https://rhn.redhat.com/cve/CVE-2008-2079.html","cve_year":"2008","cve_id":"2079","crc32":"90150381"}],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T08:49:57.795Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://dev.mysql.com/doc/refman/5.0/en/releasenotes-es-5-0-60.html"},{"name":"SUSE-SR:2008:017","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.html"},{"name":"USN-671-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/USN-671-1"},{"name":"mysql-myisam-security-bypass(42267)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/42267"},{"name":"1019995","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1019995"},{"name":"31681","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/31681"},{"name":"31687","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/31687"},{"name":"oval:org.mitre.oval:def:10133","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10133"},{"name":"31226","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/31226"},{"name":"RHSA-2009:1289","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2009-1289.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://dev.mysql.com/doc/refman/4.1/en/news-4-1-24.html"},{"name":"RHSA-2008:0768","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2008-0768.html"},{"name":"30134","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/30134"},{"name":"32769","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32769"},{"name":"APPLE-SA-2009-09-10-2","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html"},{"name":"MDVSA-2008:149","tags":["vendor-advisory","x_refsource_MANDRIVA","x_transferred"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:149"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://dev.mysql.com/doc/refman/5.1/en/news-5-1-24.html"},{"name":"32222","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32222"},{"name":"ADV-2008-1472","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/1472/references"},{"name":"31066","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/31066"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.apple.com/kb/HT3865"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://dev.mysql.com/doc/refman/6.0/en/news-6-0-5.html"},{"name":"36701","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/36701"},{"name":"RHSA-2008:0505","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2008-0505.html"},{"name":"ADV-2008-2780","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/2780"},{"name":"29106","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/29106"},{"name":"RHSA-2008:0510","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2008-0510.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://bugs.mysql.com/bug.php?id=32167"},{"name":"MDVSA-2008:150","tags":["vendor-advisory","x_refsource_MANDRIVA","x_transferred"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:150"},{"name":"DSA-1608","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2008/dsa-1608"},{"name":"36566","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/36566"},{"name":"APPLE-SA-2008-10-09","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.apple.com/kb/HT3216"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-03-15T00:00:00.000Z","descriptions":[{"lang":"en","value":"MySQL 4.1.x before 4.1.24, 5.0.x before 5.0.60, 5.1.x before 5.1.24, and 6.0.x before 6.0.5 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are within the MySQL home data directory, which can point to tables that are created in the future."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-28T12:57:01.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://dev.mysql.com/doc/refman/5.0/en/releasenotes-es-5-0-60.html"},{"name":"SUSE-SR:2008:017","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.html"},{"name":"USN-671-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/USN-671-1"},{"name":"mysql-myisam-security-bypass(42267)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/42267"},{"name":"1019995","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1019995"},{"name":"31681","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/31681"},{"name":"31687","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/31687"},{"name":"oval:org.mitre.oval:def:10133","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10133"},{"name":"31226","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/31226"},{"name":"RHSA-2009:1289","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2009-1289.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://dev.mysql.com/doc/refman/4.1/en/news-4-1-24.html"},{"name":"RHSA-2008:0768","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2008-0768.html"},{"name":"30134","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/30134"},{"name":"32769","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32769"},{"name":"APPLE-SA-2009-09-10-2","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html"},{"name":"MDVSA-2008:149","tags":["vendor-advisory","x_refsource_MANDRIVA"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:149"},{"tags":["x_refsource_CONFIRM"],"url":"http://dev.mysql.com/doc/refman/5.1/en/news-5-1-24.html"},{"name":"32222","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32222"},{"name":"ADV-2008-1472","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/1472/references"},{"name":"31066","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/31066"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.apple.com/kb/HT3865"},{"tags":["x_refsource_CONFIRM"],"url":"http://dev.mysql.com/doc/refman/6.0/en/news-6-0-5.html"},{"name":"36701","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/36701"},{"name":"RHSA-2008:0505","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2008-0505.html"},{"name":"ADV-2008-2780","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/2780"},{"name":"29106","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/29106"},{"name":"RHSA-2008:0510","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2008-0510.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://bugs.mysql.com/bug.php?id=32167"},{"name":"MDVSA-2008:150","tags":["vendor-advisory","x_refsource_MANDRIVA"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:150"},{"name":"DSA-1608","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2008/dsa-1608"},{"name":"36566","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/36566"},{"name":"APPLE-SA-2008-10-09","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.apple.com/kb/HT3216"}]}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2008-2079","datePublished":"2008-05-05T16:00:00.000Z","dateReserved":"2008-05-05T00:00:00.000Z","dateUpdated":"2024-08-07T08:49:57.795Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-05-05 16:20:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:H/Au:S/C:P/I:P/A:P","baseScore":4.6,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mysql:mysql:*:*:*:*:*:*:*:*","versionStartIncluding":"4.1.0","versionEndExcluding":"4.1.24","matchCriteriaId":"56C895D3-2949-4B14-B059-F0E29D977982"},{"vulnerable":true,"criteria":"cpe:2.3:a:mysql:mysql:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0.0","versionEndExcluding":"5.0.60","matchCriteriaId":"027481EF-83CF-40AF-8223-572B7915845F"},{"vulnerable":true,"criteria":"cpe:2.3:a:mysql:mysql:*:*:*:*:*:*:*:*","versionStartIncluding":"5.1.0","versionEndExcluding":"5.1.24","matchCriteriaId":"7F5416CD-0CEB-4C41-AE28-2A9C2B5600A7"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0.0","versionEndExcluding":"6.0.5","matchCriteriaId":"CA6A87CA-DA11-4B91-A3E9-6437042BDC1A"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*","matchCriteriaId":"0F92AB32-E7DE-43F4-B877-1F41FA162EC7"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:lts:*:*:*","matchCriteriaId":"5C18C3CD-969B-4AA3-AE3A-BA4A188F8BFF"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:7.10:*:*:*:*:*:*:*","matchCriteriaId":"823BF8BE-2309-4F67-A5E2-EAD98F723468"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:lts:*:*:*","matchCriteriaId":"C91D2DBF-6DA7-4BA2-9F29-8BD2725A4701"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"2079","Ordinal":"1","Title":"CVE-2008-2079","CVE":"CVE-2008-2079","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"2079","Ordinal":"1","NoteData":"MySQL 4.1.x before 4.1.24, 5.0.x before 5.0.60, 5.1.x before 5.1.24, and 6.0.x before 6.0.5 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are within the MySQL home data directory, which can point to tables that are created in the future.","Type":"Description","Title":"CVE-2008-2079"},{"CveYear":"2008","CveId":"2079","Ordinal":"2","NoteData":"2008-05-05","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"2079","Ordinal":"3","NoteData":"2017-09-28","Type":"Other","Title":"Modified"}]}}}