CVE-2005-0711

NameCVE-2005-0711
DescriptionMySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, uses predictable file names when creating temporary tables, which allows local users with CREATE TEMPORARY TABLE privileges to overwrite arbitrary files via a symlink attack.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-707-1
NVD severitylow (attack range: local)

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
mysqlsourcewoody3.23.49-8.11lowDSA-707-1
mysql-dfsgsource(unstable)4.0.24low
mysql-dfsg-4.1source(unstable)4.1.10alow

Search for package or bug name: Reporting problems