Nessus Plugin #11378

Plugin Index

Note: This file has been created from a downloaded version of the Nessus Plugins from http://www.nessus.org/. Therefore, the information here can be outdated.

MySQL mysqld Privilege Escalation Vulnerability

Family:
Remote file access
Category:
infos
Copyright:
This script is Copyright (C) 2003 StrongHoldNet
Summary:
Checks for the remote MySQL version
Version:
$Revision: 1.3 $
Cve_id:
CAN-2003-0150
Bugtraq_id:
7052
Xrefs:
-
Description:

You are running a version of MySQL which is older than version 3.23.56.
It is vulnerable to a vulnerability that may allow the mysqld service
to start with elevated privileges.

An attacker can exploit this vulnerability by creating a DATADIR/my.cnf
that includes the line 'user=root' under the '[mysqld]' option section.

When the mysqld service is executed, it will run as the root
user instead of the default user.

Risk factor : High
Solution : Upgrade to at least version 3.23.56
Generiert am 27.04.2005 um 18:49:54 Uhr.