MySQL 'sql/sql_table.cc' CREATE TABLE Security Bypass Vulnerability
BID:38043
Info
MySQL 'sql/sql_table.cc' CREATE TABLE Security Bypass Vulnerability
| Bugtraq ID: | 38043 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-7247 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 05 2008 12:00AM |
| Updated: | Apr 13 2015 08:24PM |
| Credit: | <br>Ingo Strwing |
| Vulnerable: |
Ubuntu Ubuntu Linux 9.10 sparc Ubuntu Ubuntu Linux 9.10 powerpc Ubuntu Ubuntu Linux 9.10 lpia Ubuntu Ubuntu Linux 9.10 i386 Ubuntu Ubuntu Linux 9.10 amd64 Ubuntu Ubuntu Linux 9.04 sparc Ubuntu Ubuntu Linux 9.04 powerpc Ubuntu Ubuntu Linux 9.04 lpia Ubuntu Ubuntu Linux 9.04 i386 Ubuntu Ubuntu Linux 9.04 amd64 Ubuntu Ubuntu Linux 8.10 sparc Ubuntu Ubuntu Linux 8.10 powerpc Ubuntu Ubuntu Linux 8.10 lpia Ubuntu Ubuntu Linux 8.10 i386 Ubuntu Ubuntu Linux 8.10 amd64 Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 10.10 powerpc Ubuntu Ubuntu Linux 10.10 i386 Ubuntu Ubuntu Linux 10.10 ARM Ubuntu Ubuntu Linux 10.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise 11 SP1 SuSE SUSE Linux Enterprise 11 SuSE SUSE Linux Enterprise 10 SP3 SuSE SUSE Linux Enterprise 10 SP2 S.u.S.E. openSUSE 11.2 S.u.S.E. openSUSE 11.1 S.u.S.E. openSUSE 11.0 Pardus Linux 2009 0 MySQL AB MySQL 6.0.8 MySQL AB MySQL 6.0.7 MySQL AB MySQL 6.0.6 MySQL AB MySQL 6.0.4 MySQL AB MySQL 6.0.3 MySQL AB MySQL 6.0.2 MySQL AB MySQL 6.0.1 MySQL AB MySQL 6.0 MySQL AB MySQL 5.1.41 MySQL AB MySQL 5.1.39 MySQL AB MySQL 5.1.38 MySQL AB MySQL 5.1.37 MySQL AB MySQL 5.1.36 MySQL AB MySQL 5.1.35 MySQL AB MySQL 5.1.34 MySQL AB MySQL 5.1.33 MySQL AB MySQL 5.1.32 MySQL AB MySQL 5.1.31 MySQL AB MySQL 5.1.30 MySQL AB MySQL 5.1.26 MySQL AB MySQL 5.1.23 MySQL AB MySQL 5.1.22 MySQL AB MySQL 5.1.18 MySQL AB MySQL 5.1.17 MySQL AB MySQL 5.1.16 MySQL AB MySQL 5.1.15 MySQL AB MySQL 5.1.14 MySQL AB MySQL 5.1.13 MySQL AB MySQL 5.1.12 MySQL AB MySQL 5.1.11 MySQL AB MySQL 5.1.10 MySQL AB MySQL 5.1.9 MySQL AB MySQL 5.1.6 MySQL AB MySQL 5.1.5 MySQL AB MySQL 5.0.88 MySQL AB MySQL 5.0.75 MySQL AB MySQL 5.0.66 MySQL AB MySQL 5.0.60 MySQL AB MySQL 5.0.52 MySQL AB MySQL 5.0.51 MySQL AB MySQL 5.0.50 MySQL AB MySQL 5.0.49 MySQL AB MySQL 5.0.48 MySQL AB MySQL 5.0.47 MySQL AB MySQL 5.0.46 MySQL AB MySQL 5.0.45 MySQL AB MySQL 5.0.44 MySQL AB MySQL 5.0.42 MySQL AB MySQL 5.0.40 MySQL AB MySQL 5.0.39 MySQL AB MySQL 5.0.38 MySQL AB MySQL 5.0.37 MySQL AB MySQL 5.0.36 MySQL AB MySQL 5.0.33 MySQL AB MySQL 5.0.32 MySQL AB MySQL 5.0.27 MySQL AB MySQL 5.0.26 MySQL AB MySQL 5.0.24 MySQL AB MySQL 5.0.22 -1-0.1 MySQL AB MySQL 5.0.22 MySQL AB MySQL 5.0.21 MySQL AB MySQL 5.0.20 MySQL AB MySQL 5.0.19 MySQL AB MySQL 5.0.18 MySQL AB MySQL 5.0.4 MySQL AB MySQL 5.0.3 MySQL AB MySQL 5.0.2 MySQL AB MySQL 5.0.1 MySQL AB MySQL 5.0 .0-alpha MySQL AB MySQL 5.0 .0-0 MySQL AB MySQL 5.0.51a MySQL AB MySQL 5.0 Mandriva Linux Mandrake 2010.0 x86_64 Mandriva Linux Mandrake 2010.0 Mandriva Linux Mandrake 2009.1 x86_64 Mandriva Linux Mandrake 2009.1 Gentoo Linux Apple Mac OS X Server 10.6.2 Apple Mac OS X Server 10.6.1 Apple Mac OS X Server 10.6 |
| Not Vulnerable: |
MySQL AB MySQL 6.0.9 Apple Mac OS X Server 10.6.3 |
Discussion
MySQL 'sql/sql_table.cc' CREATE TABLE Security Bypass Vulnerability
MySQL is prone to a security-bypass vulnerability.
An attacker can exploit this issue to bypass certain security restrictions and gain access to table files created by other users.
The following are vulnerable:
MySQL 5.0.x through 5.0.88
MySQL 5.1.x through 5.1.41
MySQL 6.0 (prior to 6.0.9-alpha)
MySQL is prone to a security-bypass vulnerability.
An attacker can exploit this issue to bypass certain security restrictions and gain access to table files created by other users.
The following are vulnerable:
MySQL 5.0.x through 5.0.88
MySQL 5.1.x through 5.1.41
MySQL 6.0 (prior to 6.0.9-alpha)
Exploit / POC
MySQL 'sql/sql_table.cc' CREATE TABLE Security Bypass Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
MySQL 'sql/sql_table.cc' CREATE TABLE Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Ubuntu Ubuntu Linux 9.10 sparc
Apple Mac OS X Server 10.6
Apple Mac OS X Server 10.6.1
Apple Mac OS X Server 10.6.2
Solution:
Updates are available. Please see the references for more information.
Ubuntu Ubuntu Linux 9.10 sparc
-
Ubuntu libmysqlclient16_5.1.37-1ubuntu5.1_sparc.deb
http://ports.ubuntu.com/pool/main/m/mysql-dfsg-5.1/libmysqlclient16_5. 1.37-1ubuntu5.1_sparc.deb -
Ubuntu libmysqld-dev_5.1.37-1ubuntu5.1_sparc.deb
http://ports.ubuntu.com/pool/main/m/mysql-dfsg-5.1/libmysqld-dev_5.1.3 7-1ubuntu5.1_sparc.deb -
Ubuntu libmysqld-pic_5.1.37-1ubuntu5.1_sparc.deb
http://ports.ubuntu.com/pool/main/m/mysql-dfsg-5.1/libmysqld-pic_5.1.3 7-1ubuntu5.1_sparc.deb -
Ubuntu mysql-client-5.1_5.1.37-1ubuntu5.1_sparc.deb
http://ports.ubuntu.com/pool/main/m/mysql-dfsg-5.1/mysql-client-5.1_5. 1.37-1ubuntu5.1_sparc.deb -
Ubuntu mysql-server-5.1_5.1.37-1ubuntu5.1_sparc.deb
http://ports.ubuntu.com/pool/main/m/mysql-dfsg-5.1/mysql-server-5.1_5. 1.37-1ubuntu5.1_sparc.deb -
Ubuntu mysql-server-core-5.1_5.1.37-1ubuntu5.1_sparc.deb
http://ports.ubuntu.com/pool/main/m/mysql-dfsg-5.1/mysql-server-core-5 .1_5.1.37-1ubuntu5.1_sparc.deb
Apple Mac OS X Server 10.6
-
Apple MacOSXServerUpdCombo10.6.3.dmg
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.6.1
-
Apple MacOSXServerUpdCombo10.6.3.dmg
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.6.2
-
Apple MacOSXServerUpd10.6.3.dmg
http://www.apple.com/support/downloads/
References
MySQL 'sql/sql_table.cc' CREATE TABLE Security Bypass Vulnerability
References:
References:
- Bug 543619 - (CVE-2008-7247) CVE-2008-7247 MySQL: Intended access restrictions (Jan Lieskovsky)
- Bug #39277 Creation of table with data and/or index files in data home directory (Ingo Strüwing )
- MySQL Homepage (Oracle)
- Ubuntu Security Notice USN-897-1 (Ubuntu)