MySQL before 4.1.23, 5.0.x before 5.0.42, and 5.1.x before 5.1.18 does not require the DROP privilege for RENAME TABLE statements, which allows remote authenticated users to rename arbitrary tables.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mysql | Mysql | * | 4.1.22 (including) |
Mysql | Mysql | 5.0 (including) | 5.0.42 (excluding) |
Mysql | Mysql | 5.1 (including) | 5.1.18 (excluding) |
Red Hat Enterprise Linux 4 | RedHat | mysql-0:4.1.22-2.el4 | * |
Red Hat Enterprise Linux 5 | RedHat | mysql-0:5.0.45-7.el5 | * |
Red Hat Web Application Stack for RHEL 4 | RedHat | mysql-0:5.0.44-1.el4s1.1 | * |
Mysql-dfsg-5.0 | Ubuntu | dapper | * |
Mysql-dfsg-5.0 | Ubuntu | devel | * |
Mysql-dfsg-5.0 | Ubuntu | edgy | * |
Mysql-dfsg-5.0 | Ubuntu | feisty | * |
Mysql-dfsg-5.0 | Ubuntu | upstream | * |