Vulnerability Description
The mysqlhotcopy script in mysql 4.0.20 and earlier, when using the scp method from the mysql-server package, allows local users to overwrite arbitrary files via a symlink attack on temporary files.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Mysql | <= 4.0.20 |
References
- http://packages.debian.org/changelogs/pool/main/m/mysql-dfsg/mysql-dfsg_4.0.20-1
- http://www.ciac.org/ciac/bulletins/p-018.shtml
- http://www.debian.org/security/2004/dsa-540
- http://www.redhat.com/support/errata/RHSA-2004-597.htmlPatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17030
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
- http://packages.debian.org/changelogs/pool/main/m/mysql-dfsg/mysql-dfsg_4.0.20-1
- http://www.ciac.org/ciac/bulletins/p-018.shtml
- http://www.debian.org/security/2004/dsa-540
- http://www.redhat.com/support/errata/RHSA-2004-597.htmlPatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17030
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
FAQ
What is CVE-2004-0457?
CVE-2004-0457 is a vulnerability with a CVSS score of 4.6 (MEDIUM). The mysqlhotcopy script in mysql 4.0.20 and earlier, when using the scp method from the mysql-server package, allows local users to overwrite arbitrary files via a symlink attack on temporary files.
How severe is CVE-2004-0457?
CVE-2004-0457 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-0457?
Check the references section above for vendor advisories and patch information. Affected products include: Oracle Mysql.