Back

MEDIUM

MySQL: Intended access restrictions bypass

Published Nov 30, 2009

Description

sql/sql_table.cc in MySQL 5.0.x through 5.0.88, 5.1.x through 5.1.41, and 6.0 before 6.0.9-alpha, when the data home directory contains a symlink to a different filesystem, allows remote authenticated users to bypass intended access restrictions by calling CREATE TABLE with a (1) DATA DIRECTORY or (2) INDEX DIRECTORY argument referring to a subdirectory that requires following this symlink.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue did not affect the versions of mysql as shipped with Red Hat Enterprise Linux 3, 4, or 5.

Metrics

Weaknesses (1)

References (17)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 30, 2009
Updated Aug 7, 2024
Reserved Nov 25, 2009
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Nov 4, 2009