CVE Vulnerabilities

CVE-2007-2692

Published: May 16, 2007 | Modified: Dec 17, 2019
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The mysql_change_db function in MySQL 5.0.x before 5.0.40 and 5.1.x before 5.1.18 does not restore THD::db_access privileges when returning from SQL SECURITY INVOKER stored routines, which allows remote authenticated users to gain privileges.

Affected Software

Name Vendor Start Version End Version
Mysql Mysql 5.0.0 (including) 5.0.0 (including)
Mysql Mysql 5.0.1 (including) 5.0.1 (including)
Mysql Mysql 5.0.2 (including) 5.0.2 (including)
Mysql Mysql 5.0.3 (including) 5.0.3 (including)
Mysql Mysql 5.0.4 (including) 5.0.4 (including)
Mysql Mysql 5.0.5 (including) 5.0.5 (including)
Mysql Mysql 5.0.5.0.21 (including) 5.0.5.0.21 (including)
Mysql Mysql 5.0.10 (including) 5.0.10 (including)
Mysql Mysql 5.0.15 (including) 5.0.15 (including)
Mysql Mysql 5.0.16 (including) 5.0.16 (including)
Mysql Mysql 5.0.17 (including) 5.0.17 (including)
Mysql Mysql 5.0.20 (including) 5.0.20 (including)
Mysql Mysql 5.0.22.1.0.1 (including) 5.0.22.1.0.1 (including)
Mysql Mysql 5.0.24 (including) 5.0.24 (including)
Mysql Mysql 5.1.5 (including) 5.1.5 (including)
Mysql Oracle 5.0.0-alpha (including) 5.0.0-alpha (including)
Mysql Oracle 5.0.3-beta (including) 5.0.3-beta (including)
Mysql Oracle 5.0.6 (including) 5.0.6 (including)
Mysql Oracle 5.0.7 (including) 5.0.7 (including)
Mysql Oracle 5.0.8 (including) 5.0.8 (including)
Mysql Oracle 5.0.9 (including) 5.0.9 (including)
Mysql Oracle 5.0.11 (including) 5.0.11 (including)
Mysql Oracle 5.0.12 (including) 5.0.12 (including)
Mysql Oracle 5.0.13 (including) 5.0.13 (including)
Mysql Oracle 5.0.14 (including) 5.0.14 (including)
Mysql Oracle 5.0.18 (including) 5.0.18 (including)
Mysql Oracle 5.0.19 (including) 5.0.19 (including)
Mysql Oracle 5.0.21 (including) 5.0.21 (including)
Mysql Oracle 5.0.22 (including) 5.0.22 (including)
Mysql Oracle 5.0.27 (including) 5.0.27 (including)
Mysql Oracle 5.0.33 (including) 5.0.33 (including)
Mysql Oracle 5.0.37 (including) 5.0.37 (including)
Mysql Oracle 5.1.1 (including) 5.1.1 (including)
Mysql Oracle 5.1.2 (including) 5.1.2 (including)
Mysql Oracle 5.1.3 (including) 5.1.3 (including)
Mysql Oracle 5.1.4 (including) 5.1.4 (including)
Mysql Oracle 5.1.6 (including) 5.1.6 (including)
Mysql Oracle 5.1.7 (including) 5.1.7 (including)
Mysql Oracle 5.1.8 (including) 5.1.8 (including)
Mysql Oracle 5.1.9 (including) 5.1.9 (including)
Mysql Oracle 5.1.10 (including) 5.1.10 (including)
Mysql Oracle 5.1.11 (including) 5.1.11 (including)
Mysql Oracle 5.1.12 (including) 5.1.12 (including)
Mysql Oracle 5.1.13 (including) 5.1.13 (including)
Mysql Oracle 5.1.14 (including) 5.1.14 (including)
Mysql Oracle 5.1.15 (including) 5.1.15 (including)
Mysql Oracle 5.1.16 (including) 5.1.16 (including)
Mysql Oracle 5.1.17 (including) 5.1.17 (including)
Mysql-dfsg-5.0 Ubuntu dapper *
Mysql-dfsg-5.0 Ubuntu devel *
Mysql-dfsg-5.0 Ubuntu edgy *
Mysql-dfsg-5.0 Ubuntu feisty *
Mysql-dfsg-5.0 Ubuntu gutsy *
Mysql-dfsg-5.0 Ubuntu upstream *
Red Hat Enterprise Linux 5 RedHat mysql-0:5.0.45-7.el5 *
Red Hat Web Application Stack for RHEL 4 RedHat mysql-0:5.0.44-1.el4s1.1 *

References