sql/sql_table.cc in MySQL 5.0.x through 5.0.88, 5.1.x through 5.1.41, and 6.0 before 6.0.9-alpha, when the data home directory contains a symlink to a different filesystem, allows remote authenticated users to bypass intended access restrictions by calling CREATE TABLE with a (1) DATA DIRECTORY or (2) INDEX DIRECTORY argument referring to a subdirectory that requires following this symlink.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2009-11-30 09:30
Updated : 2019-12-17 12:26
NVD link : CVE-2008-7247
Mitre link : CVE-2008-7247
JSON object : View
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')
Products Affected
oracle
- mysql
mysql
- mysql