First published: Fri Oct 11 2002(Updated: )
Buffer overflow in MySQL daemon (mysqld) before 3.23.50, and 4.0 beta before 4.02, on the Win32 platform, allows local users to execute arbitrary code via a long "datadir" parameter in the my.ini initialization file, whose permissions on Windows allow Full Control to the Everyone group.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle MySQL | =3.23.49 | |
Oracle MySQL | =4.0.0 | |
Oracle MySQL | =4.0.1 | |
All of | ||
Any of | ||
Oracle MySQL | <3.23.50 | |
Oracle MySQL | >=4.0.0<=4.0.2 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.