LOW
security flaw
Published Mar 11, 2005
2.1
LOWCVSS 2.0
EPSS 1.70%
Description
MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, uses predictable file names when creating temporary tables, which allows local users with CREATE TEMPORARY TABLE privileges to overwrite arbitrary files via a symlink attack.
Affected products
No data.
OR
- 4.1.0
- 4.1.3
- 4.1.10
- 3.23.49
- 4.0.0
- 4.0.1
- 4.0.2
- 4.0.3
- 4.0.4
- 4.0.5
- 4.0.5a
- 4.0.6
- 4.0.7
- 4.0.7
- 4.0.8
- 4.0.8
- 4.0.9
- 4.0.9
- 4.0.10
- 4.0.11
- 4.0.11
- 4.0.12
- 4.0.13
- 4.0.14
- 4.0.15
- 4.0.18
- 4.0.20
- 4.0.21
- 4.0.23
- 4.1.0
- 4.1.2
- 4.1.3
- 4.1.4
- 4.1.5
No data.
Red Hat Desktop version 3 Extras
n/a
Fixed · RHSA-2005:348
Red Hat Enterprise Linux 3
mysql-0:3.23.58-15.RHEL3.1
Fixed · RHSA-2005:334
Red Hat Enterprise Linux 4
mysql-0:4.1.10a-1.RHEL4.1
Fixed · RHSA-2005:334
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Desktop version 3 Extras | n/a | Fixed | RHSA-2005:348 |
| Red Hat Enterprise Linux 3 | mysql-0:3.23.58-15.RHEL3.1 | Fixed | RHSA-2005:334 |
| Red Hat Enterprise Linux 4 | mysql-0:4.1.10a-1.RHEL4.1 | Fixed | RHSA-2005:334 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (18)
- http://archives.neohapsis.com/archives/vulnwatch/2005-q1/0082.html mailing-listx_refsource_VULNWATCHExploit
- http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html vendor-advisoryx_refsource_APPLE
- http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html vendor-advisoryx_refsource_APPLE
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-101864-1 vendor-advisoryx_refsource_SUNALERT
- http://www.debian.org/security/2005/dsa-707 vendor-advisoryx_refsource_DEBIANExploit
- http://www.gentoo.org/security/en/glsa/glsa-200503-19.xml vendor-advisoryx_refsource_GENTOOPatch
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:060 vendor-advisoryx_refsource_MANDRAKE
- http://www.novell.com/linux/security/advisories/2005_19_mysql.html vendor-advisoryx_refsource_SUSEPatch
- http://www.redhat.com/support/errata/RHSA-2005-334.html vendor-advisoryx_refsource_REDHATPatch
- http://www.redhat.com/support/errata/RHSA-2005-348.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/bid/12781 vdb-entryx_refsource_BIDPatch
- http://www.trustix.org/errata/2005/0009/ vendor-advisoryx_refsource_TRUSTIXPatch
- https://access.redhat.com/security/cve/CVE-2005-0711 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1617562 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2005-0711
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9591 vdb-entrysignaturex_refsource_OVAL
- https://usn.ubuntu.com/96-1/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2005-0711
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 11, 2005
Updated Aug 7, 2024
Reserved Mar 11, 2005
Link CVE-2005-0711
CISA Vulnrichment
Updated n/a