CVE Vulnerabilities

CVE-2007-5969

Published: Dec 10, 2007 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.1 HIGH
AV:N/AC:H/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

MySQL Community Server 5.0.x before 5.0.51, Enterprise Server 5.0.x before 5.0.52, Server 5.1.x before 5.1.23, and Server 6.0.x before 6.0.4, when a table relies on symlinks created through explicit DATA DIRECTORY and INDEX DIRECTORY options, allows remote authenticated users to overwrite system table information and gain privileges via a RENAME TABLE statement that changes the symlink to point to an existing file.

Affected Software

Name Vendor Start Version End Version
Mysql_server Mysql 5.1.22 (including) 5.1.22 (including)
Mysql_server Mysql 6.0 (including) 6.0 (including)
Mysql_server Mysql 6.0.1 (including) 6.0.1 (including)
Mysql_server Mysql 6.0.2 (including) 6.0.2 (including)
Mysql_server Mysql 6.0.3 (including) 6.0.3 (including)

References