First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 17386
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Daniel Ahlberg (RETIRED) <aliz@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 17386 depends on: Show dependency tree
Bug 17386 blocks:
Votes: 0    Show votes for this bug    Vote for this bug

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2003-03-12 12:27 0000
Re: MySQL user can be changed to root 
 
From:  
Sergei Golubchik <serg@mysql.com> 
 
 
To:  
"Guido A.J. Stevens" <gyst@nfg.nl> 
 
 
Date:  
Monday 20.08.38 
 
 
Hi! 
 
Both to bugtraq and mysql list: 
 
This issue has been adressed in 3.23.56 (release build is started 
today), and some steps were taken to alleviate the threat. 
 
In particular, MySQL will no longer read config files that are 
world-writeable (and SELECT ... OUTFILE always creates world-writeable 
files). Also, unlike other options, for --user option the first one will 
have the precedence. So if --user is set in /etc/my.cnf (as it is 
recommended in the manual), datadir/my.cnf will not be able to override 
it. 
 
Fixing this issue in more robust way would mean introducing too big and 
incompatible changes into stable version, thus breaking lots of 
installations. It is to be done in 4.1. 
  
Regards, 
Sergei 
 
On Mar 10, Guido A.J. Stevens wrote: 
>  
> I can confirm this privilege escalation in mysql-server   3.23.49-8.2  
> (debian/stable on linux/i386). Any mysql user with file privileges can  
> trick the mysql server into running as root on restart of the mysql  
> subsystem. 
>  
> bugsman@libero.it wrote: 
>  
> > mysql>SELECT * INTO OUTFILE '/path/to/mysql/datadir/my.cnf' FROM hack 
>  
> > Now, when the mysql server will be restarted, the user option in our 
> > datadir my.cnf will override the one in /etc/my.cnf and mysql server will 
> > run as root 
 
--  
MySQL Development Team 
   __  ___     ___ ____  __ 
  /  |/  /_ __/ __/ __ \/ /   Sergei Golubchik <serg@mysql.com> 
 / /|_/ / // /\ \/ /_/ / /__  MySQL AB, http://www.mysql.com/ 
/_/  /_/\_, /___/\___\_\___/  Osnabrueck, Germany 
       <___/

------- Comment #1 From Daniel Ahlberg (RETIRED) 2003-03-18 13:13:29 0000 -------
glsa sent 

First Last Prev Next    No search results available      Search page      Enter new bug