CVE-2008-4098 - CVE House
Back to Database
Status published Medium CVE-2008-4098

MySQL before 5.0.67 allows local users to bypass certain privilege...

Vulnerability Description

MySQL before 5.0.67 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL home data directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4097.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2008-4098

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

ubuntu linux, debian linux, mysql
Vulnerable Versions:
6.06, 7.10, 8.04, 8.10, 9.04, 9.10, 5.0, 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.0.4, 5.0.5, 5.0.10, 5.0.15, 5.0.16, 5.0.17, 5.0.20, 5.0.24, 5.0.30, 5.0.36, 5.0.44, 5.0.54, 5.0.56, 5.0.60, 5.0.66, 5.0.23, 5.0.25, 5.0.26, 5.0.28, 5.0.32, 5.0.34, 5.0.38, 5.0.40, 5.0.41, 5.0.42, 5.0.45, 5.0.46, 5.0.48, 5.0.50, 5.0.51, 5.0.52, 5.0.58, 5.0.62, 5.0.64

Timeline

Official Publish: September 17th, 2008
Last Modified: August 7th, 2024
Added to House: July 18th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.