CVE Vulnerabilities

CVE-2007-2692

Published: May 16, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The mysql_change_db function in MySQL 5.0.x before 5.0.40 and 5.1.x before 5.1.18 does not restore THD::db_access privileges when returning from SQL SECURITY INVOKER stored routines, which allows remote authenticated users to gain privileges.

Affected Software

NameVendorStart VersionEnd Version
MysqlMysql5.0.0 (including)5.0.0 (including)
MysqlMysql5.0.1 (including)5.0.1 (including)
MysqlMysql5.0.2 (including)5.0.2 (including)
MysqlMysql5.0.3 (including)5.0.3 (including)
MysqlMysql5.0.4 (including)5.0.4 (including)
MysqlMysql5.0.5 (including)5.0.5 (including)
MysqlMysql5.0.5.0.21 (including)5.0.5.0.21 (including)
MysqlMysql5.0.10 (including)5.0.10 (including)
MysqlMysql5.0.15 (including)5.0.15 (including)
MysqlMysql5.0.16 (including)5.0.16 (including)
MysqlMysql5.0.17 (including)5.0.17 (including)
MysqlMysql5.0.20 (including)5.0.20 (including)
MysqlMysql5.0.22.1.0.1 (including)5.0.22.1.0.1 (including)
MysqlMysql5.0.24 (including)5.0.24 (including)
MysqlMysql5.1.5 (including)5.1.5 (including)
MysqlOracle5.0.0-alpha (including)5.0.0-alpha (including)
MysqlOracle5.0.3-beta (including)5.0.3-beta (including)
MysqlOracle5.0.6 (including)5.0.6 (including)
MysqlOracle5.0.7 (including)5.0.7 (including)
MysqlOracle5.0.8 (including)5.0.8 (including)
MysqlOracle5.0.9 (including)5.0.9 (including)
MysqlOracle5.0.11 (including)5.0.11 (including)
MysqlOracle5.0.12 (including)5.0.12 (including)
MysqlOracle5.0.13 (including)5.0.13 (including)
MysqlOracle5.0.14 (including)5.0.14 (including)
MysqlOracle5.0.18 (including)5.0.18 (including)
MysqlOracle5.0.19 (including)5.0.19 (including)
MysqlOracle5.0.21 (including)5.0.21 (including)
MysqlOracle5.0.22 (including)5.0.22 (including)
MysqlOracle5.0.27 (including)5.0.27 (including)
MysqlOracle5.0.33 (including)5.0.33 (including)
MysqlOracle5.0.37 (including)5.0.37 (including)
MysqlOracle5.1.1 (including)5.1.1 (including)
MysqlOracle5.1.2 (including)5.1.2 (including)
MysqlOracle5.1.3 (including)5.1.3 (including)
MysqlOracle5.1.4 (including)5.1.4 (including)
MysqlOracle5.1.6 (including)5.1.6 (including)
MysqlOracle5.1.7 (including)5.1.7 (including)
MysqlOracle5.1.8 (including)5.1.8 (including)
MysqlOracle5.1.9 (including)5.1.9 (including)
MysqlOracle5.1.10 (including)5.1.10 (including)
MysqlOracle5.1.11 (including)5.1.11 (including)
MysqlOracle5.1.12 (including)5.1.12 (including)
MysqlOracle5.1.13 (including)5.1.13 (including)
MysqlOracle5.1.14 (including)5.1.14 (including)
MysqlOracle5.1.15 (including)5.1.15 (including)
MysqlOracle5.1.16 (including)5.1.16 (including)
MysqlOracle5.1.17 (including)5.1.17 (including)
Red Hat Enterprise Linux 5RedHatmysql-0:5.0.45-7.el5*
Red Hat Web Application Stack for RHEL 4RedHatmysql-0:5.0.44-1.el4s1.1*
Mysql-dfsg-5.0Ubuntudapper*
Mysql-dfsg-5.0Ubuntudevel*
Mysql-dfsg-5.0Ubuntuedgy*
Mysql-dfsg-5.0Ubuntufeisty*
Mysql-dfsg-5.0Ubuntugutsy*
Mysql-dfsg-5.0Ubuntuupstream*

References