First published: Thu Aug 19 2004(Updated: )
The mysqlhotcopy script in mysql 4.0.20 and earlier, when using the scp method from the mysql-server package, allows local users to overwrite arbitrary files via a symlink attack on temporary files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MySQL | <=4.0.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0457 is considered a moderate severity vulnerability due to its potential for local users to exploit the symlink attack.
To fix CVE-2004-0457, upgrade to MySQL version 4.0.21 or later which addresses this issue.
The potential impact of CVE-2004-0457 includes unauthorized overwriting of arbitrary files by local users.
Local users of MySQL version 4.0.20 and earlier are primarily affected by CVE-2004-0457.
The mysqlhotcopy script in the MySQL server package is involved in CVE-2004-0457.