{ "CVE_data_meta": { "ASSIGNER": "cve@mitre.org", "ID": "CVE-2003-0150", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "n/a", "version": { "version_data": [ { "version_value": "n/a" } ] } } ] }, "vendor_name": "n/a" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "MySQL 3.23.55 and earlier creates world-writeable files and allows mysql users to gain root privileges by using the \"SELECT * INFO OUTFILE\" operator to overwrite a configuration file and cause mysql to run as root upon restart, as demonstrated by modifying my.cnf." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "n/a" } ] } ] }, "references": { "reference_data": [ { "name": "20030318 [OpenPKG-SA-2003.022] OpenPKG Security Advisory (mysql)", "refsource": "BUGTRAQ", "url": "http://marc.info/?l=bugtraq&m=104800948128630&w=2" }, { "name": "oval:org.mitre.oval:def:442", "refsource": "OVAL", "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A442" }, { "name": "CLA-2003:743", "refsource": "CONECTIVA", "url": "http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000743" }, { "name": "20030318 GLSA: mysql (200303-14)", "refsource": "BUGTRAQ", "url": "http://marc.info/?l=bugtraq&m=104802285012750&w=2" }, { "name": "DSA-303", "refsource": "DEBIAN", "url": "http://www.debian.org/security/2003/dsa-303" }, { "name": "mysql-datadir-root-privileges(11510)", "refsource": "XF", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/11510" }, { "name": "RHSA-2003:094", "refsource": "REDHAT", "url": "http://rhn.redhat.com/errata/RHSA-2003-094.html" }, { "name": "MDKSA-2003:057", "refsource": "MANDRAKE", "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2003:057" }, { "name": "VU#203897", "refsource": "CERT-VN", "url": "http://www.kb.cert.org/vuls/id/203897" }, { "name": "20030310 Re: MySQL user can be changed to root", "refsource": "BUGTRAQ", "url": "http://marc.info/?l=bugtraq&m=104739810523433&w=2" }, { "name": "ESA-20030324-012", "refsource": "ENGARDE", "url": "http://www.linuxsecurity.com/advisories/engarde_advisory-3046.html" }, { "name": "RHSA-2003:093", "refsource": "REDHAT", "url": "http://www.redhat.com/support/errata/RHSA-2003-093.html" }, { "name": "7052", "refsource": "BID", "url": "http://www.securityfocus.com/bid/7052" }, { "name": "20030308 MySQL_user_can_be_changed_to_root?", "refsource": "BUGTRAQ", "url": "http://marc.info/?l=bugtraq&m=104715840202315&w=2" } ] } }