Description
Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database whose name includes a "_" (underscore), grants privileges to other databases that have similar names, which can allow the user to conduct unauthorized activities.
Affected products
- openpkg / openpkg2.1 – 2.1
- openpkg / openpkg2.2 – 2.2
- openpkg / openpkgcurrent – current
- oracle / mysql3.20 – 3.20
- oracle / mysql3.20.32a – 3.20.32a
- oracle / mysql3.21 – 3.21
- oracle / mysql3.22 – 3.22
- oracle / mysql3.22.26 – 3.22.26
- oracle / mysql3.22.27 – 3.22.27
- oracle / mysql3.22.28 – 3.22.28
- oracle / mysql3.22.29 – 3.22.29
- oracle / mysql3.22.30 – 3.22.30
- oracle / mysql3.22.32 – 3.22.32
- oracle / mysql3.23 – 3.23
- oracle / mysql3.23.2 – 3.23.2
- oracle / mysql3.23.3 – 3.23.3
- oracle / mysql3.23.4 – 3.23.4
- oracle / mysql3.23.5 – 3.23.5
- oracle / mysql3.23.8 – 3.23.8
- oracle / mysql3.23.9 – 3.23.9
- oracle / mysql3.23.10 – 3.23.10
- oracle / mysql3.23.22 – 3.23.22
- oracle / mysql3.23.23 – 3.23.23
- oracle / mysql3.23.24 – 3.23.24
- oracle / mysql3.23.25 – 3.23.25
- oracle / mysql3.23.26 – 3.23.26
- oracle / mysql3.23.27 – 3.23.27
- oracle / mysql3.23.28 – 3.23.28
- oracle / mysql3.23.28 – 3.23.28
- oracle / mysql3.23.29 – 3.23.29
- oracle / mysql3.23.30 – 3.23.30
- oracle / mysql3.23.31 – 3.23.31
- oracle / mysql3.23.32 – 3.23.32
- oracle / mysql3.23.33 – 3.23.33
- oracle / mysql3.23.34 – 3.23.34
- oracle / mysql3.23.36 – 3.23.36
- oracle / mysql3.23.37 – 3.23.37
- oracle / mysql3.23.38 – 3.23.38
- oracle / mysql3.23.39 – 3.23.39
- oracle / mysql3.23.40 – 3.23.40
- oracle / mysql3.23.41 – 3.23.41
- oracle / mysql3.23.42 – 3.23.42
- oracle / mysql3.23.43 – 3.23.43
- oracle / mysql3.23.44 – 3.23.44
- oracle / mysql3.23.45 – 3.23.45
- oracle / mysql3.23.46 – 3.23.46
- oracle / mysql3.23.47 – 3.23.47
- oracle / mysql3.23.48 – 3.23.48
- oracle / mysql3.23.49 – 3.23.49
- oracle / mysql3.23.50 – 3.23.50
- oracle / mysql3.23.51 – 3.23.51
- oracle / mysql3.23.52 – 3.23.52
- oracle / mysql3.23.53 – 3.23.53
- oracle / mysql3.23.53a – 3.23.53a
- oracle / mysql3.23.54 – 3.23.54
- oracle / mysql3.23.54a – 3.23.54a
- oracle / mysql3.23.55 – 3.23.55
- oracle / mysql3.23.56 – 3.23.56
- oracle / mysql3.23.58 – 3.23.58
- oracle / mysql3.23.59 – 3.23.59
- oracle / mysql4.0.0 – 4.0.0
- oracle / mysql4.0.1 – 4.0.1
- oracle / mysql4.0.2 – 4.0.2
- oracle / mysql4.0.3 – 4.0.3
- oracle / mysql4.0.4 – 4.0.4
- oracle / mysql4.0.5 – 4.0.5
- oracle / mysql4.0.5a – 4.0.5a
- oracle / mysql4.0.6 – 4.0.6
- oracle / mysql4.0.7 – 4.0.7
- oracle / mysql4.0.7 – 4.0.7
- oracle / mysql4.0.8 – 4.0.8
- oracle / mysql4.0.8 – 4.0.8
- oracle / mysql4.0.9 – 4.0.9
- oracle / mysql4.0.9 – 4.0.9
- oracle / mysql4.0.10 – 4.0.10
- oracle / mysql4.0.11 – 4.0.11
- oracle / mysql4.0.11 – 4.0.11
- oracle / mysql4.0.12 – 4.0.12
- oracle / mysql4.0.13 – 4.0.13
- oracle / mysql4.0.14 – 4.0.14
- oracle / mysql4.0.15 – 4.0.15
- oracle / mysql4.0.18 – 4.0.18
- oracle / mysql4.0.20 – 4.0.20
- RedHat / enterprise_linux3.0 – 3.0
- RedHat / enterprise_linux3.0 – 3.0
- RedHat / enterprise_linux3.0 – 3.0
- RedHat / enterprise_linux_desktop3.0 – 3.0
- SUSE / suse_linux8.0 – 8.0
- SUSE / suse_linux8.1 – 8.1
- SUSE / suse_linux8.2 – 8.2
- SUSE / suse_linux9.0 – 9.0
- SUSE / suse_linux9.0 – 9.0
- SUSE / suse_linux9.1 – 9.1
- SUSE / suse_linux9.2 – 9.2
- trustix / secure_linux1.5 – 1.5
- trustix / secure_linux2.0 – 2.0
- trustix / secure_linux2.1 – 2.1
- Ubuntu / ubuntu_linux4.1 – 4.1
- Ubuntu / ubuntu_linux4.1 – 4.1
References
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/17783
- MISChttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000947
- MISChttp://www.redhat.com/support/errata/RHSA-2004-611.html
- VENDOR_ADVISORYhttp://www.debian.org/security/2005/dsa-707
- VENDOR_ADVISORYhttp://www.mandriva.com/security/advisories?name=MDKSA-2005:070
- VENDOR_ADVISORYhttps://www.ubuntu.com/usn/usn-32-1/
- MISChttp://www.redhat.com/support/errata/RHSA-2004-597.html
- MISChttp://www.ciac.org/ciac/bulletins/p-018.shtml