VulnerabilityModified
CVE-2004-0957
Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database whose name includes a "_" (underscore), grants privileges to other databases that have similar names, which can allow the user to conduct unauthorized…
MEDIUM 6.8EPSS 2.43%
Does this matter?
Lower severity and a low EPSS score (2.43%). Track it; it rarely justifies an emergency change on its own.
Description
Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database whose name includes a "_" (underscore), grants privileges to other databases that have similar names, which can allow the user to conduct unauthorized activities.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 2.43% probability · 83th percentile
- CISA KEV
- Not listed
- Affected
- openpkg/openpkg · oracle/mysql · redhat/enterprise linux · redhat/enterprise linux desktop · suse/suse linux · trustix/secure linux · ubuntu/ubuntu linux
- Source
- cve@mitre.org
References
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000947
- http://www.ciac.org/ciac/bulletins/p-018.shtml
- http://www.debian.org/security/2005/dsa-707
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:070
- http://www.redhat.com/support/errata/RHSA-2004-597.html
- http://www.redhat.com/support/errata/RHSA-2004-611.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17783
- https://www.ubuntu.com/usn/usn-32-1/
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000947
- http://www.ciac.org/ciac/bulletins/p-018.shtml
- http://www.debian.org/security/2005/dsa-707
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:070
- http://www.redhat.com/support/errata/RHSA-2004-597.html
- http://www.redhat.com/support/errata/RHSA-2004-611.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17783
- https://www.ubuntu.com/usn/usn-32-1/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.