Security Advisory

CVE-2003-0150

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2003-03-21 05:00:00
Last updated 2024-08-08 01:43:36
Assigner mitre
State PUBLISHED

Description

MySQL 3.23.55 and earlier creates world-writeable files and allows mysql users to gain root privileges by using the "SELECT * INFO OUTFILE" operator to overwrite a configuration file and cause mysql to run as root upon restart, as demonstrated by modifying my.cnf.