FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2005-1636

This CVE name corresponds to:

Entered Topic
2005-07-09 mysql-server -- insecure temporary file creation

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2005-1636
Phase Assigned(20050517)

Description

mysql_install_db in MySQL 4.1.x before 4.1.12 and 5.x up to 5.0.4 creates the mysql_install_db.X file with a predictable filename and insecure permissions, which allows local users to execute arbitrary SQL commands by modifying the file's contents.

References

Source Reference
FULLDISC 20050517 MySQL < 4.0.12 && MySQL <= 5.0.4 : Insecure tmp
MISC http://www.zataz.net/adviso/mysql-05172005.txt
CONFIRM https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=158688
MANDRIVA MDKSA-2006:045
REDHAT RHSA-2005:685
BID 13660
OVAL oval:org.mitre.oval:def:9504
SECUNIA 15369
SECUNIA 17080