Upstream information

CVE-2008-4097 at MITRE

Description

MySQL 5.0.51a allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are associated with symlinks within pathnames for subdirectories of the MySQL home data directory, which are followed when tables are created in the future. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-2079.

SUSE information

Overall state of this security issue: Ignore

This issue is currently rated as having moderate severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 4.6
Vector AV:N/AC:H/Au:S/C:P/I:P/A:P
Access Vector Network
Access Complexity High
Authentication Single
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact Partial
SUSE Bugzilla entries: 425079 [RESOLVED / FIXED], 497546 [RESOLVED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
Novell Linux Desktop 9 SDK for x86
Novell Linux Desktop 9 SDK for x86_64
SLES SDK 9 for IBM S/390 and IBM zSeries
SLES SDK 9 for IBM iSeries and IBM pSeries
SLES SDK 9 for IBM zSeries
SLES SDK 9 for IPF
SLES SDK 9 for X86-64
SLES SDK 9 for x86
  • mysql-bench >= 4.0.18-32.37
core9.ia64
core9.x86
core9.ppc
core9.s390
core9.x86-64
sles9-nld.x86-64
core9.ppc
sles9-nlpos.x86
core9.x86-64
sles9-nld.x86
core9.x86
sles9-nld.x86-64
core9.s390x
core9.ia64
core9.s390
core9.s390x
sles9-nld.x86
sles9-oes.x86
YOU Patch Nr: 12256
Novell Linux Desktop 9 for x86
Open Enterprise Server
  • mysql >= 4.0.18-32.37
  • mysql-Max >= 4.0.18-32.37
  • mysql-client >= 4.0.18-32.37
  • mysql-devel >= 4.0.18-32.37
  • mysql-shared >= 4.0.18-32.37
core9.ia64
core9.x86
core9.ppc
core9.s390
core9.x86-64
sles9-nld.x86-64
core9.ppc
sles9-nlpos.x86
core9.x86-64
sles9-nld.x86
core9.x86
sles9-nld.x86-64
core9.s390x
core9.ia64
core9.s390
core9.s390x
sles9-nld.x86
sles9-oes.x86
YOU Patch Nr: 12256
Novell Linux Desktop 9 for x86_64
  • mysql >= 4.0.18-32.37
  • mysql-Max >= 4.0.18-32.37
  • mysql-bench >= 4.0.18-32.37
  • mysql-client >= 4.0.18-32.37
  • mysql-devel >= 4.0.18-32.37
  • mysql-shared >= 4.0.18-32.37
core9.ia64
core9.x86
core9.ppc
core9.s390
core9.x86-64
sles9-nld.x86-64
core9.ppc
sles9-nlpos.x86
core9.x86-64
sles9-nld.x86
core9.x86
sles9-nld.x86-64
core9.s390x
core9.ia64
core9.s390
core9.s390x
sles9-nld.x86
sles9-oes.x86
YOU Patch Nr: 12256
SUSE Linux Enterprise SDK 10 SP2
  • mysql >= 5.0.26-12.22
  • mysql-Max >= 5.0.26-12.22
  • mysql-bench >= 5.0.26-12.22
  • mysql-client >= 5.0.26-12.22
  • mysql-devel >= 5.0.26-12.22
  • mysql-shared >= 5.0.26-12.22
sled10.x86-64
sle10-sp2-sdk.ia64
sled10-sp2.x86
sles10.x86
sles10-sp2-debuginfo.x86
sle10-sp2-sdk.x86
sle10-sp1-sdk.ia64
sles10-sp2.x86
sles10-sp2.s390x
sles10-sp2-debuginfo.ppc
sles10-sp2-debuginfo.s390x
sle10-sp2-sdk.s390x
sles10-sp2.x86-64
sles10.s390x
sles10.x86-64
sles10-sp2.ppc
sles10-sp2.ia64
sle10-sp2-sdk.ppc
sled10.x86
sle10-sp2-sdk.x86-64
sles10-sp2-debuginfo.ia64
sle10-sp1-sdk.ppc
sled10-sp2.x86-64
sles10-sp2-debuginfo.x86-64
sles10.ia64
sle10-sp1-sdk.x86-64
sle10-sp1-sdk.s390x
sles10.ppc
sle10-sp1-sdk.x86
ZYPP Patch Nr: 5618
SUSE Linux Enterprise SDK 10 SP2
  • mysql >= 5.0.26-12.22
  • mysql-Max >= 5.0.26-12.22
  • mysql-bench >= 5.0.26-12.22
  • mysql-client >= 5.0.26-12.22
  • mysql-devel >= 5.0.26-12.22
  • mysql-shared >= 5.0.26-12.22
  • mysql-shared-x86 >= 5.0.26-12.22
sled10.x86-64
sle10-sp2-sdk.ia64
sled10-sp2.x86
sles10.x86
sles10-sp2-debuginfo.x86
sle10-sp2-sdk.x86
sle10-sp1-sdk.ia64
sles10-sp2.x86
sles10-sp2.s390x
sles10-sp2-debuginfo.ppc
sles10-sp2-debuginfo.s390x
sle10-sp2-sdk.s390x
sles10-sp2.x86-64
sles10.s390x
sles10.x86-64
sles10-sp2.ppc
sles10-sp2.ia64
sle10-sp2-sdk.ppc
sled10.x86
sle10-sp2-sdk.x86-64
sles10-sp2-debuginfo.ia64
sle10-sp1-sdk.ppc
sled10-sp2.x86-64
sles10-sp2-debuginfo.x86-64
sles10.ia64
sle10-sp1-sdk.x86-64
sle10-sp1-sdk.s390x
sles10.ppc
sle10-sp1-sdk.x86
ZYPP Patch Nr: 5618
SUSE Linux Enterprise SDK 10 SP2
  • mysql >= 5.0.26-12.22
  • mysql-Max >= 5.0.26-12.22
  • mysql-bench >= 5.0.26-12.22
  • mysql-client >= 5.0.26-12.22
  • mysql-devel >= 5.0.26-12.22
  • mysql-shared >= 5.0.26-12.22
  • mysql-shared-64bit >= 5.0.26-12.22
sled10.x86-64
sle10-sp2-sdk.ia64
sled10-sp2.x86
sles10.x86
sles10-sp2-debuginfo.x86
sle10-sp2-sdk.x86
sle10-sp1-sdk.ia64
sles10-sp2.x86
sles10-sp2.s390x
sles10-sp2-debuginfo.ppc
sles10-sp2-debuginfo.s390x
sle10-sp2-sdk.s390x
sles10-sp2.x86-64
sles10.s390x
sles10.x86-64
sles10-sp2.ppc
sles10-sp2.ia64
sle10-sp2-sdk.ppc
sled10.x86
sle10-sp2-sdk.x86-64
sles10-sp2-debuginfo.ia64
sle10-sp1-sdk.ppc
sled10-sp2.x86-64
sles10-sp2-debuginfo.x86-64
sles10.ia64
sle10-sp1-sdk.x86-64
sle10-sp1-sdk.s390x
sles10.ppc
sle10-sp1-sdk.x86
ZYPP Patch Nr: 5618
SUSE Linux Enterprise SDK 10 SP2
  • mysql >= 5.0.26-12.22
  • mysql-Max >= 5.0.26-12.22
  • mysql-bench >= 5.0.26-12.22
  • mysql-client >= 5.0.26-12.22
  • mysql-devel >= 5.0.26-12.22
  • mysql-shared >= 5.0.26-12.22
  • mysql-shared-32bit >= 5.0.26-12.22
sled10.x86-64
sle10-sp2-sdk.ia64
sled10-sp2.x86
sles10.x86
sles10-sp2-debuginfo.x86
sle10-sp2-sdk.x86
sle10-sp1-sdk.ia64
sles10-sp2.x86
sles10-sp2.s390x
sles10-sp2-debuginfo.ppc
sles10-sp2-debuginfo.s390x
sle10-sp2-sdk.s390x
sles10-sp2.x86-64
sles10.s390x
sles10.x86-64
sles10-sp2.ppc
sles10-sp2.ia64
sle10-sp2-sdk.ppc
sled10.x86
sle10-sp2-sdk.x86-64
sles10-sp2-debuginfo.ia64
sle10-sp1-sdk.ppc
sled10-sp2.x86-64
sles10-sp2-debuginfo.x86-64
sles10.ia64
sle10-sp1-sdk.x86-64
sle10-sp1-sdk.s390x
sles10.ppc
sle10-sp1-sdk.x86
ZYPP Patch Nr: 5618
openSUSE 11.0
  • mysql-debuginfo >= 5.0.51a-27.2
  • mysql-debugsource >= 5.0.51a-27.2
openSUSE 11.0
  • libmysqlclient-devel >= 5.0.51a-27.2
  • libmysqlclient15 >= 5.0.51a-27.2
  • libmysqlclient15-32bit >= 5.0.51a-27.2
  • libmysqlclient15-64bit >= 5.0.51a-27.2
  • libmysqlclient_r15 >= 5.0.51a-27.2
  • libmysqlclient_r15-32bit >= 5.0.51a-27.2
  • libmysqlclient_r15-64bit >= 5.0.51a-27.2
  • mysql >= 5.0.51a-27.2
  • mysql-Max >= 5.0.51a-27.2
  • mysql-bench >= 5.0.51a-27.2
  • mysql-client >= 5.0.51a-27.2
  • mysql-debug >= 5.0.51a-27.2
  • mysql-tools >= 5.0.51a-27.2