---
title: "CVE-2008-4097\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2008-4097?format=md
keywords: index, follow
---

# CVE-2008-4097

Publication date 18 September 2008

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

MySQL 5.0.51a allows local users to bypass certain privilege checks by
calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or
(2) INDEX DIRECTORY arguments that are associated with symlinks within
pathnames for subdirectories of the MySQL home data directory, which are
followed when tables are created in the future. NOTE: this vulnerability
exists because of an incomplete fix for CVE-2008-2079.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| mysql-dfsg-5.0 | 8.10 intrepid | Not affected |
| 8.04 LTS hardy | Fixed 5.0.51a-3ubuntu5.4 |
| 7.10 gutsy | Fixed 5.0.45-1ubuntu3.4 |
| 7.04 feisty | Ignored end of life, was needs-triage |
| 6.06 LTS dapper | Fixed 5.0.22-0ubuntu6.06.11 |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4097)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2008-4097)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2008-4097)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2008-4097)

### Related Ubuntu Security Notices (USN)

+ [USN-671-1](https://usn.ubuntu.com/USN-671-1)
+ MySQL vulnerabilities
+ 17 November 2008

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2008-4097>
