Summary
The remote host is missing an update to mysql
announced via advisory DSA 647-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20647-1
Insight
Javier Fernandez-Sanguino Pena from the Debian Security Audit Project discoverd a temporary file vulnerability in the mysqlaccess script of MySQL that could allow an unprivileged user to let root overwrite arbitrary files via a symlink attack and could also could unveil the contents of a temporary file which might contain sensitive information.
For the stable distribution (woody) this problem has been fixed in version 3.23.49-8.9.
For the unstable distribution (sid) this problem has been fixed in version 4.0.23-3 of mysql-dfsg and in version 4.1.8a-6 of mysql-dfsg-4.1.
We recommend that you upgrade your mysql packages.
Severity
Classification
-
CVE CVE-2005-0004 -
CVSS Base Score: 4.6
AV:L/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities