oval:org.mitre.oval:def:8156

Definition Id: oval:org.mitre.oval:def:8156
 
Oval ID: oval:org.mitre.oval:def:8156
Title: MySQL 5.1 Privilege Bypass with DATA/INDEX DIRECTORY
Description: MySQL 5.1.x before 5.1.41 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL data home directory, related to incorrect calculation of the mysql_unpacked_real_data_home value. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4098 and CVE-2008-2079.
Family: windows Class: vulnerability
Reference(s): CVE-2009-4030
Version: 3
Platform(s): Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Server 2003
Microsoft Windows Vista
Microsoft Windows 7
Microsoft Windows Server 2008
Product(s): MySQL Server 5.1
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:8297
 
Oval ID: oval:org.mitre.oval:def:8297
Title: MySQL 5.1 is installed
Description: MySQL Server 5.1 is installed
Family: windows Class: inventory
Reference(s): cpe:/a:mysql:mysql:5.1
Version: 9
Platform(s): Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Server 2003
Microsoft Windows Vista
Microsoft Windows Server 2008
Microsoft Windows 7
Microsoft Windows Server 2008 R2
Microsoft Windows 8
Microsoft Windows 8.1
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Product(s): MySQL Server 5.1
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:8156