Unrated severityNVD Advisory· Published Aug 19, 2013· Updated Apr 29, 2026
CVE-2013-2162
CVE-2013-2162
Description
Race condition in the post-installation script (mysql-server-5.5.postinst) for MySQL Server 5.5 for Debian GNU/Linux and Ubuntu Linux creates a configuration file with world-readable permissions before restricting the permissions, which allows local users to read the file and obtain sensitive information such as credentials.
Affected products
4cpe:2.3:o:canonical:ubuntu_linux:10.04:-:lts:*:*:*:*:*+ 3 more
- cpe:2.3:o:canonical:ubuntu_linux:10.04:-:lts:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:12.04:-:lts:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:13.04:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- bugs.debian.org/cgi-bin/bugreport.cginvdExploit
- secunia.com/advisories/54300nvdVendor Advisory
- ubuntu.com/usn/usn-1909-1nvdVendor Advisory
- seclists.org/oss-sec/2013/q2/528nvd
- www.debian.org/security/2013/dsa-2818nvd
- www.securityfocus.com/bid/60424nvd
News mentions
0No linked articles in our index yet.