Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 300177 - <dev-db/mysql-5.1.41 Privilege Check Bypass (5.1.x only) (CVE-2009-4030)
Summary: <dev-db/mysql-5.1.41 Privilege Check Bypass (5.1.x only) (CVE-2009-4030)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial (vote)
Assignee: Gentoo Security
URL: http://dev.mysql.com/doc/refman/5.1/e...
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2010-01-08 16:17 UTC by Alex Legler (RETIRED)
Modified: 2010-02-01 15:07 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alex Legler (RETIRED) archtester gentoo-dev Security 2010-01-08 16:17:23 UTC
CVE-2009-4030 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-4030):
  MySQL 5.1.x before 5.1.41 allows local users to bypass certain
  privilege checks by calling CREATE TABLE on a MyISAM table with
  modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are
  originally associated with pathnames without symlinks, and that can
  point to tables created at a future time at which a pathname is
  modified to contain a symlink to a subdirectory of the MySQL data
  home directory, related to incorrect calculation of the
  mysql_unpacked_real_data_home value.  NOTE: this vulnerability exists
  because of an incomplete fix for CVE-2008-4098 and CVE-2008-2079.
Comment 1 Robin Johnson archtester Gentoo Infrastructure gentoo-dev Security 2010-02-01 01:32:19 UTC
Fixed 5.1 ebuilds in the tree now.
Comment 2 Tobias Heinlein (RETIRED) gentoo-dev 2010-02-01 15:07:49 UTC
Thanks.