First published: Fri May 12 2006(Updated: )
MySQL Manager in Apple Mac OS X 10.3.9 and 10.4.6, when setting up a new MySQL database server, does not use the "New MySQL root password" that is provided, which causes the MySQL root password to be blank and allows local users to gain full privileges to that database.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Yosemite | =10.4.6 | |
macOS Yosemite | =10.3.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1451 is considered a high severity vulnerability due to the potential for unauthorized local user access to the MySQL database.
To mitigate CVE-2006-1451, set a strong root password for MySQL after installing the database server.
CVE-2006-1451 affects users of MySQL Manager on Apple Mac OS X versions 10.3.9 and 10.4.6.
Exploitation of CVE-2006-1451 can lead to full privileges for local users on the MySQL database due to a blank root password.
There is no specific patch available, but users should manually set the MySQL root password to avoid the vulnerability.