Vulnerability Description
The mysqlaccess script in MySQL 4.0.23 and earlier, 4.1.x before 4.1.10, 5.0.x before 5.0.3, and other versions including 3.x, allows local users to overwrite arbitrary files or read temporary files via a symlink attack on temporary files.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Mysql | >= 4.0.0, < 4.0.23 |
| Debian | Debian Linux | 3.0 |
| Mariadb | Mariadb | >= 5.5.0, < 5.5.66 |
Related Weaknesses (CWE)
References
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000947Third Party Advisory
- http://lists.mysql.com/internals/20600Third Party Advisory
- http://marc.info/?l=bugtraq&m=110608297217224&w=2Third Party Advisory
- http://mysql.osuosl.org/doc/mysql/en/News-4.1.10.htmlBroken Link
- http://secunia.com/advisories/13867Not Applicable
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-101864-1Broken Link
- http://www.debian.org/security/2005/dsa-647PatchVendor Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:036Broken Link
- http://www.securityfocus.com/bid/12277PatchThird Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18922Third Party AdvisoryVDB Entry
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000947Third Party Advisory
- http://lists.mysql.com/internals/20600Third Party Advisory
- http://marc.info/?l=bugtraq&m=110608297217224&w=2Third Party Advisory
- http://mysql.osuosl.org/doc/mysql/en/News-4.1.10.htmlBroken Link
- http://secunia.com/advisories/13867Not Applicable
FAQ
What is CVE-2005-0004?
CVE-2005-0004 is a vulnerability with a CVSS score of 4.6 (MEDIUM). The mysqlaccess script in MySQL 4.0.23 and earlier, 4.1.x before 4.1.10, 5.0.x before 5.0.3, and other versions including 3.x, allows local users to overwrite arbitrary files or read temporary files v...
How severe is CVE-2005-0004?
CVE-2005-0004 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-0004?
Check the references section above for vendor advisories and patch information. Affected products include: Oracle Mysql, Debian Debian Linux, Mariadb Mariadb.