MySQL 3.23.55 and earlier creates world-writeable files and allows mysql users to gain root privileges by using the "SELECT * INFO OUTFILE" operator to overwrite a configuration file and cause mysql to run as root upon restart, as demonstrated by modifying my.cnf.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2003-03-24 05:00
Updated : 2019-10-07 16:41
NVD link : CVE-2003-0150
Mitre link : CVE-2003-0150
CVE.ORG link : CVE-2003-0150
JSON object : View
Products Affected
oracle
- mysql
CWE