FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

MySQL insecure temporary file creation (mysqlbug)

Affected packages
4.0 <= mysql-client < 4.0.20
4.1 <= mysql-client < 4.1.1_2
5.0 <= mysql-client < 5.0.0_2

Details

VuXML ID 2e129846-8fbb-11d8-8b29-0020ed76ef5a
Discovery 2004-03-25
Entry 2004-04-16
Modified 2004-05-21

Shaun Colley reports that the script `mysqlbug' included with MySQL sometimes creates temporary files in an unsafe manner. As a result, an attacker may create a symlink in /tmp so that if another user invokes `mysqlbug' and quits without making any changes, an arbitrary file may be overwritten with the bug report template.

References

Bugtraq ID 9976
CVE Name CVE-2004-0381
Message http://marc.theaimsgroup.com/?l=bugtraq&m=108023246916294&w=2
URL http://bugs.mysql.com/bug.php?id=3284