Jump to content

Advisories MDVSA-2008:149: Updated mysql packages fix vulnerabilities


paul
 Share

Recommended Posts

Sergei Golubchik found that MySQL did not properly validate optional

data or index directory paths given in a CREATE TABLE statement; as

well it would not, under certain conditions, prevent two databases

from using the same paths for data or index files. This could allow

an authenticated user with appropriate privilege to create tables in

one database to read and manipulate data in tables later created in

other databases, regardless of GRANT privileges (CVE-2008-2079).

 

The updated packages have been patched to correct this issue.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...