MySQL 3.23.55 and earlier creates world-writeable files and allows mysql users to gain root privileges by using the "SELECT * INFO OUTFILE" operator to overwrite a configuration file and cause mysql to run as root upon restart, as demonstrated by modifying my.cnf.
Get an AI-powered plain-language explanation of this vulnerability and remediation steps.
Login to generate AI explanation28 reference(s) from NVD