
Last updated: Thu May 23 11:52:32 EDT 2013
CVE Publication rate: 12.0
NVD provides four mailing lists to the public. For information and subscription instructions please visit NVD Mailing Lists
Vulnerability Workload Index: 6.38
** DISPUTED ** MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the FILE privilege to users who should not have administrative privileges, allows remote authenticated users to gain privileges by leveraging the FILE privilege to create files as the MySQL administrator. NOTE: the vendor disputes this issue, stating that this is only a vulnerability when the administrator does not follow recommendations in the product's installation documentation. NOTE: it could be argued that this should not be included in CVE because it is a configuration issue.
Per http://www.openwall.com/lists/oss-security/2012/12/02/3, this vulnerability is for linux-based software installations.
By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to nvd@nist.gov.
| Configuration 1 |
| AND |
| OR |
| * cpe:/a:oracle:mysql:5.5.19 |
| * cpe:/a:mariadb:mariadb:5.5.28a |
| OR |
| cpe:/o:linux:linux |