CVE Vulnerabilities

CVE-2007-5969

Published: Dec 10, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.1 HIGH
AV:N/AC:H/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

MySQL Community Server 5.0.x before 5.0.51, Enterprise Server 5.0.x before 5.0.52, Server 5.1.x before 5.1.23, and Server 6.0.x before 6.0.4, when a table relies on symlinks created through explicit DATA DIRECTORY and INDEX DIRECTORY options, allows remote authenticated users to overwrite system table information and gain privileges via a RENAME TABLE statement that changes the symlink to point to an existing file.

Affected Software

NameVendorStart VersionEnd Version
Mysql_serverMysql5.1.22 (including)5.1.22 (including)
Mysql_serverMysql6.0 (including)6.0 (including)
Mysql_serverMysql6.0.1 (including)6.0.1 (including)
Mysql_serverMysql6.0.2 (including)6.0.2 (including)
Mysql_serverMysql6.0.3 (including)6.0.3 (including)
Red Hat Enterprise Linux 4RedHatmysql-0:4.1.20-3.RHEL4.1.el4_6.1*
Red Hat Enterprise Linux 5RedHatmysql-0:5.0.22-2.2.el5_1.1*
Red Hat Web Application Stack for RHEL 4RedHatmysql-0:5.0.44-2.el4s1.1*
Mysql-dfsg-5.0Ubuntudapper*
Mysql-dfsg-5.0Ubuntuedgy*
Mysql-dfsg-5.0Ubuntufeisty*
Mysql-dfsg-5.0Ubuntugutsy*
Mysql-dfsg-5.0Ubuntuupstream*

References