Bug #53748 INDEX/DATA DIRECTORY realpath(3) race allows access to server data dir
Submitted: 18 May 2010 12:30 Modified: 27 May 2010 20:20
Reporter: Matt McCutchen Email Updates:
Status: Verified Impact on me:
None 
Category:MySQL Server: MyISAM storage engine Severity:S3 (Non-critical)
Version:5.1.46 OS:Linux (Fedora 12)
Assigned to: CPU Architecture:Any
Tags: Security

File: Maximum allowed size is 50MB.
Description:
Privacy:

If the data you need to attach is more than 50MB, you should create a compressed archive of the data, split it to 50MB chunks, and upload each of them as a separate attachment.

To split a large file:

[18 May 2010 12:31] Matt McCutchen
Demonstration kit

Attachment: mysql-symlink-race.tar.bz2 (application/x-bzip2, text), 5.96 KiB.

[26 May 2010 20:28] Matt McCutchen
User table schema file for MySQL 5.5.4

Attachment: user-schema-5.5.4.sql (application/octet-stream, text), 2.81 KiB.