CVE Vulnerabilities

CVE-2007-5969

Published: Dec 10, 2007 | Modified: Oct 15, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.1 HIGH
AV:N/AC:H/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

MySQL Community Server 5.0.x before 5.0.51, Enterprise Server 5.0.x before 5.0.52, Server 5.1.x before 5.1.23, and Server 6.0.x before 6.0.4, when a table relies on symlinks created through explicit DATA DIRECTORY and INDEX DIRECTORY options, allows remote authenticated users to overwrite system table information and gain privileges via a RENAME TABLE statement that changes the symlink to point to an existing file.

Affected Software

Name Vendor Start Version End Version
Mysql_server Mysql 5.1.22 5.1.22
Mysql_server Mysql 6.0 6.0
Mysql_server Mysql 6.0.1 6.0.1
Mysql_server Mysql 6.0.2 6.0.2
Mysql_server Mysql 6.0.3 6.0.3
Red Hat Application Stack v2 for Enterprise Linux RedHat mysql *
Red Hat Enterprise Linux 4 RedHat mysql-0:4.1.20-3.RHEL4.1.el4_6.1 *
Red Hat Enterprise Linux 5 RedHat mysql-0:5.0.22-2.2.el5_1.1 *
Mysql-dfsg-5.0 Ubuntu dapper *
Mysql-dfsg-5.0 Ubuntu edgy *
Mysql-dfsg-5.0 Ubuntu feisty *
Mysql-dfsg-5.0 Ubuntu gutsy *
Mysql-dfsg-5.0 Ubuntu upstream *

References