MySQL mysql_install_db Insecure Temporary File Creation Vulnerability
BID:13660
Info
MySQL mysql_install_db Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 13660 |
| Class: | Design Error |
| CVE: |
CVE-2005-1636 |
| Remote: | No |
| Local: | Yes |
| Published: | May 17 2005 12:00AM |
| Updated: | Dec 14 2006 06:44PM |
| Credit: | Discovery is credited to Eric Romang <[email protected]>. |
| Vulnerable: |
Redhat Fedora Core4 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux AS 4 Redhat Desktop 4.0 MySQL AB MySQL 5.0.4 MySQL AB MySQL 5.0.3 MySQL AB MySQL 5.0.2 MySQL AB MySQL 5.0.1 MySQL AB MySQL 5.0 .0-alpha MySQL AB MySQL 5.0 .0-0 MySQL AB MySQL 4.0.11 -gamma MySQL AB MySQL 4.0.11 MySQL AB MySQL 4.0.10 MySQL AB MySQL 4.0.9 -gamma MySQL AB MySQL 4.0.9 MySQL AB MySQL 4.0.8 -gamma MySQL AB MySQL 4.0.8 MySQL AB MySQL 4.0.7 -gamma MySQL AB MySQL 4.0.7 MySQL AB MySQL 4.0.6 MySQL AB MySQL 4.0.5 a MySQL AB MySQL 4.0.5 MySQL AB MySQL 4.0.4 MySQL AB MySQL 4.0.3 MySQL AB MySQL 4.0.2 MySQL AB MySQL 4.0.1 MySQL AB MySQL 4.0 .0 Mandriva Linux Mandrake 10.2 x86_64 Mandriva Linux Mandrake 10.2 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: |
MySQL AB MySQL 4.0.12 |
Discussion
MySQL mysql_install_db Insecure Temporary File Creation Vulnerability
MySQL is reportedly affected by a vulnerability that can allow local attackers to gain unauthorized access to the database or gain elevated privileges. This issue results from a design error due to the creation of temporary files in an insecure manner.
The vulnerability affects the 'mysql_install_db' script.
Due to the nature of the script, an attacker may create database accounts or gain elevated privileges.
MySQL versions prior to 4.0.12 and MySQL 5.x releases 5.0.4 and prior are reported to be affected.
MySQL is reportedly affected by a vulnerability that can allow local attackers to gain unauthorized access to the database or gain elevated privileges. This issue results from a design error due to the creation of temporary files in an insecure manner.
The vulnerability affects the 'mysql_install_db' script.
Due to the nature of the script, an attacker may create database accounts or gain elevated privileges.
MySQL versions prior to 4.0.12 and MySQL 5.x releases 5.0.4 and prior are reported to be affected.
Exploit / POC
MySQL mysql_install_db Insecure Temporary File Creation Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
MySQL mysql_install_db Insecure Temporary File Creation Vulnerability
Solution:
Reportedly, MySQL 4.0.12 is not affected by this issue.
Please see the referenced vendor advisories for more information.
MySQL AB MySQL 4.0.11
Solution:
Reportedly, MySQL 4.0.12 is not affected by this issue.
Please see the referenced vendor advisories for more information.
MySQL AB MySQL 4.0.11
-
Debian mysql-client-4.1_4.1.11a-4sarge1_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/m/mysql-dfsg-4.1/mysql-cl ient-4.1_4.1.11a-4sarge1_amd64.deb
References
MySQL mysql_install_db Insecure Temporary File Creation Vulnerability
References:
References:
- MySQL Homepage (Oracle)
- RHSA-2005:685-5 - mysql security update (RedHat)