MySQL before 4.1.23, 5.0.x before 5.0.42, and 5.1.x before 5.1.18 does not require the DROP privilege for RENAME TABLE statements, which allows remote authenticated users to rename arbitrary tables.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Mysql | Mysql | * | 4.1.22 (including) |
| Mysql | Mysql | 5.0 (including) | 5.0.42 (excluding) |
| Mysql | Mysql | 5.1 (including) | 5.1.18 (excluding) |
| Red Hat Enterprise Linux 4 | RedHat | mysql-0:4.1.22-2.el4 | * |
| Red Hat Enterprise Linux 5 | RedHat | mysql-0:5.0.45-7.el5 | * |
| Red Hat Web Application Stack for RHEL 4 | RedHat | mysql-0:5.0.44-1.el4s1.1 | * |
| Mysql-dfsg-5.0 | Ubuntu | dapper | * |
| Mysql-dfsg-5.0 | Ubuntu | devel | * |
| Mysql-dfsg-5.0 | Ubuntu | edgy | * |
| Mysql-dfsg-5.0 | Ubuntu | feisty | * |
| Mysql-dfsg-5.0 | Ubuntu | upstream | * |