CVE Vulnerabilities

CVE-2007-2691

Published: May 16, 2007 | Modified: Oct 19, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.9 MEDIUM
AV:N/AC:M/Au:S/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

MySQL before 4.1.23, 5.0.x before 5.0.42, and 5.1.x before 5.1.18 does not require the DROP privilege for RENAME TABLE statements, which allows remote authenticated users to rename arbitrary tables.

Affected Software

Name Vendor Start Version End Version
Mysql Mysql * 4.1.22 (including)
Mysql Mysql 5.0 (including) 5.0.42 (excluding)
Mysql Mysql 5.1 (including) 5.1.18 (excluding)
Red Hat Enterprise Linux 4 RedHat mysql-0:4.1.22-2.el4 *
Red Hat Enterprise Linux 5 RedHat mysql-0:5.0.45-7.el5 *
Red Hat Web Application Stack for RHEL 4 RedHat mysql-0:5.0.44-1.el4s1.1 *
Mysql-dfsg-5.0 Ubuntu dapper *
Mysql-dfsg-5.0 Ubuntu devel *
Mysql-dfsg-5.0 Ubuntu edgy *
Mysql-dfsg-5.0 Ubuntu feisty *
Mysql-dfsg-5.0 Ubuntu upstream *

References