CVE-2005-0711

Description

MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, uses predictable file names when creating temporary tables, which allows local users with CREATE TEMPORARY TABLE privileges to overwrite arbitrary files via a symlink attack.

Risk Information

Base Score
5.5
MODERATE
Vector
AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
0.349

Associated Vulnerability

VulnerabilityOS Platform
Vulnerability CVE-2005-0709,CVE-2005-0710,CVE-2005-0711 are affected in Mysql 4.1.10Windows
Vulnerability CVE-2005-0709,CVE-2005-0710,CVE-2005-0711 are affected in Mysql 4.1.10 (For Linux)Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234