CVE-2004-0957

Publication date 9 February 2005

Last updated 17 July 2025


Ubuntu priority

Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database whose name includes a "_" (underscore), grants privileges to other databases that have similar names, which can allow the user to conduct unauthorized activities.

Status

Package Ubuntu Release Status
mysql-dfsg 7.04 feisty Not in release
6.10 edgy
Fixed 4.0.24-10ubuntu2
6.06 LTS dapper
Fixed 4.0.24-10ubuntu2
mysql-dfsg-4.1 7.04 feisty Not in release
6.10 edgy
Fixed 4.1.15-1ubuntu5
6.06 LTS dapper
Fixed 4.1.15-1ubuntu5
mysql-dfsg-5.0 7.04 feisty
Fixed 5.0.38-0ubuntu1
6.10 edgy
Fixed 5.0.24a-9ubuntu0.1
6.06 LTS dapper
Fixed 5.0.22-0ubuntu6.06.3

References

Related Ubuntu Security Notices (USN)

    • USN-32-1
    • mysql vulnerabilities
    • 25 November 2004

Other references