Description: Jeroen van Wolffelaar has discovered a vulnerability in MySQL, potentially allowing malicious users to overwrite arbitrary files.
The copy utility "mysqlhotcopy" creates a file with an easy guessable name in an insecure manner if the scp (secure copy) method is used. This can potentially be exploited by malicious users to overwrite arbitrary files when "mysqlhotcopy" is executed by a privileged user.
This has been reported in the MySQL 4.0.20 and prior including the MySQL 3 branch.
Solution: Do not use the "mysqlhotcopy" utility on systems with untrusted users.
Provided and/or discovered by: Jeroen van Wolffelaar
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.