Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2009-4030

MySQL 5.1.x before 5.1.41 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL data home directory, related to incorrect calculation of the mysql_unpacked_real_data_home value. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4098 and CVE-2008-2079.

  • Published: Nov 30, 2009
  • Updated: Nov 8, 2023
  • CVE: CVE-2009-4030
  • Severity: Low
  • Exploit:

CVSS v2:

  • Severity: Low
  • Score: 4.4
  • AV:L/AC:M/Au:N/C:P/I:P/A:P

CWEs:

Software From Fixed in
mysql / mysql 5.1.23 5.1.23.x
mysql / mysql 5.1.32 5.1.32.x
mysql / mysql 5.1.5 5.1.5.x
oracle / mysql 5.1 5.1.x
oracle / mysql 5.1.1 5.1.1.x
oracle / mysql 5.1.2 5.1.2.x
oracle / mysql 5.1.3 5.1.3.x
oracle / mysql 5.1.4 5.1.4.x
oracle / mysql 5.1.6 5.1.6.x
oracle / mysql 5.1.7 5.1.7.x
oracle / mysql 5.1.8 5.1.8.x
oracle / mysql 5.1.9 5.1.9.x
oracle / mysql 5.1.10 5.1.10.x
oracle / mysql 5.1.11 5.1.11.x
oracle / mysql 5.1.12 5.1.12.x
oracle / mysql 5.1.13 5.1.13.x
oracle / mysql 5.1.14 5.1.14.x
oracle / mysql 5.1.15 5.1.15.x
oracle / mysql 5.1.16 5.1.16.x
oracle / mysql 5.1.17 5.1.17.x
oracle / mysql 5.1.18 5.1.18.x
oracle / mysql 5.1.19 5.1.19.x
oracle / mysql 5.1.20 5.1.20.x
oracle / mysql 5.1.21 5.1.21.x
oracle / mysql 5.1.22 5.1.22.x
oracle / mysql 5.1.30 5.1.30.x