MySQL before 4.1.21, 5.0 before 5.0.25, and 5.1 before 5.1.12, when run on case-sensitive filesystems, allows remote authenticated users to create or access a database when the database name differs only in case from a database for which they have permissions. Successful exploitation requires that MySQL runs on a system with a file system supporting case-sensitive file names.
This vulnerability is addresses in the following product releases:
MySQL, MySQL, 4.1.21
MySQL, MySQL, 5.0.25
MySQL, MySQL, 5.1.12
Publication date: Sat, 19 Aug 2006 01:04:00 +0000