PublicDate: 2004-09-28 04:00:00 UTC Candidate: CVE-2004-0457 References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0457 Description: The mysqlhotcopy script in mysql 4.0.20 and earlier, when using the scp method from the mysql-server package, allows local users to overwrite arbitrary files via a symlink attack on temporary files. Ubuntu-Description: Notes: Priority: untriaged Discovered-by: Assigned-to: CVSS: Bugs: dapper_mysql-dfsg-4.1: released (4.1.15-1ubuntu5) edgy_mysql-dfsg-4.1: released (4.1.15-1ubuntu5) feisty_mysql-dfsg-4.1: DNE devel_mysql-dfsg-4.1: DNE dapper_mysql-dfsg: released (4.0.24-10ubuntu2) edgy_mysql-dfsg: released (4.0.24-10ubuntu2) feisty_mysql-dfsg: DNE devel_mysql-dfsg: DNE dapper_mysql-dfsg-5.0: released (5.0.22-0ubuntu6.06.3) edgy_mysql-dfsg-5.0: released (5.0.24a-9ubuntu0.1) feisty_mysql-dfsg-5.0: released (5.0.38-0ubuntu1) devel_mysql-dfsg-5.0: released (5.0.38-0ubuntu1) upstream_mysql-dfsg: needs-triage upstream_mysql-dfsg-4.1: needs-triage upstream_mysql-dfsg-5.0: needs-triage