CVE-2008-2079
Last modified
CVE-2008-2079 is a vulnerability of currently unknown severity. MySQL 4.1.x before 4.1.24, 5.0.x before 5.0.60, 5.1.x before 5.1.24, and 6.0.x before 6.0.5 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are within the MySQL home data directory, which can point to tables that are created in the future.. EPSS estimates a 2.59% chance of exploitation in the next 30 days.
Description
MySQL 4.1.x before 4.1.24, 5.0.x before 5.0.60, 5.1.x before 5.1.24, and 6.0.x before 6.0.5 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are within the MySQL home data directory, which can point to tables that are created in the future.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mysql | Mysql | >= 4.1.0, < 4.1.24 |
| Mysql | Mysql | >= 5.0.0, < 5.0.60 |
| Mysql | Mysql | >= 5.1.0, < 5.1.24 |
| Oracle | Mysql | >= 6.0.0, < 6.0.5 |
| Debian | Debian Linux | 4.0 |
| Canonical | Ubuntu Linux | 6.06 |
| Canonical | Ubuntu Linux | 7.10 |
| Canonical | Ubuntu Linux | 8.04 |
References
- http://bugs.mysql.com/bug.php?id=32167Exploit, Patch, Vendor Advisory
- http://dev.mysql.com/doc/refman/4.1/en/news-4-1-24.htmlVendor Advisory
- http://dev.mysql.com/doc/refman/5.1/en/news-5-1-24.htmlVendor Advisory
- http://dev.mysql.com/doc/refman/6.0/en/news-6-0-5.htmlVendor Advisory
- http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.htmlMailing List, Third Party Advisory
- http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.htmlThird Party Advisory
- http://secunia.com/advisories/30134Third Party Advisory
- http://secunia.com/advisories/31066Third Party Advisory
- http://secunia.com/advisories/31226Third Party Advisory
- http://secunia.com/advisories/31687Third Party Advisory
- http://secunia.com/advisories/32222Third Party Advisory
- http://secunia.com/advisories/32769Third Party Advisory
- http://secunia.com/advisories/36566Third Party Advisory
- http://secunia.com/advisories/36701Third Party Advisory
- http://support.apple.com/kb/HT3216Third Party Advisory
- http://support.apple.com/kb/HT3865Third Party Advisory
- http://www.debian.org/security/2008/dsa-1608Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:149Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:150Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0505.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0510.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0768.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2009-1289.htmlThird Party Advisory
- http://www.securityfocus.com/bid/29106Patch, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/31681Patch, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1019995Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-671-1Third Party Advisory
- http://www.vupen.com/english/advisories/2008/1472/referencesThird Party Advisory
- http://www.vupen.com/english/advisories/2008/2780Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42267Third Party Advisory, VDB Entry
- http://bugs.mysql.com/bug.php?id=32167Exploit, Patch, Vendor Advisory
- http://dev.mysql.com/doc/refman/4.1/en/news-4-1-24.htmlVendor Advisory
- http://dev.mysql.com/doc/refman/5.1/en/news-5-1-24.htmlVendor Advisory
- http://dev.mysql.com/doc/refman/6.0/en/news-6-0-5.htmlVendor Advisory
- http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.htmlMailing List, Third Party Advisory
- http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.htmlThird Party Advisory
- http://secunia.com/advisories/30134Third Party Advisory
- http://secunia.com/advisories/31066Third Party Advisory
- http://secunia.com/advisories/31226Third Party Advisory
- http://secunia.com/advisories/31687Third Party Advisory
- http://secunia.com/advisories/32222Third Party Advisory
- http://secunia.com/advisories/32769Third Party Advisory
- http://secunia.com/advisories/36566Third Party Advisory
- http://secunia.com/advisories/36701Third Party Advisory
- http://support.apple.com/kb/HT3216Third Party Advisory
- http://support.apple.com/kb/HT3865Third Party Advisory
- http://www.debian.org/security/2008/dsa-1608Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:149Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:150Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0505.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0510.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0768.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2009-1289.htmlThird Party Advisory
- http://www.securityfocus.com/bid/29106Patch, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/31681Patch, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1019995Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-671-1Third Party Advisory
- http://www.vupen.com/english/advisories/2008/1472/referencesThird Party Advisory
- http://www.vupen.com/english/advisories/2008/2780Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42267Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-2079?
How severe is CVE-2008-2079?
How do I fix CVE-2008-2079?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-2073Directory traversal vulnerability in include/global.inc.php …
- CVE-2008-2074Multiple PHP remote file inclusion vulnerabilities Harris Yu…
- CVE-2008-2075Cross-site scripting (XSS) vulnerability in pic.php in Astro…
- CVE-2008-2076Directory traversal vulnerability in admin.php in ActualScri…
- CVE-2008-2077Unspecified vulnerability in Plain Black WebGUI 7.4.34 has u…
- CVE-2008-2078Robocode before 1.6.0 allows user-assisted remote attackers …
- CVE-2008-2080Stack-based buffer overflow in the Read32s_64 function in sr…
- CVE-2008-2081Directory traversal vulnerability in index.php in Siteman 2.…
- CVE-2008-2082Cross-site scripting (XSS) vulnerability in index.php in Sit…
- CVE-2008-2083SQL injection vulnerability in directory.php in Prozilla Hos…
- CVE-2008-2084SQL injection vulnerability in topics.php in the MyArticles …
- CVE-2008-2085Multiple stack-based buffer overflows in the (1) get_remote_…
Are you affected by CVE-2008-2079?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
