CVE Vulnerabilities

CVE-2007-6303

Published: Dec 10, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.5 LOW
AV:N/AC:M/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

MySQL 5.0.x before 5.0.51a, 5.1.x before 5.1.23, and 6.0.x before 6.0.4 does not update the DEFINER value of a view when the view is altered, which allows remote authenticated users to gain privileges via a sequence of statements including a CREATE SQL SECURITY DEFINER VIEW statement and an ALTER VIEW statement.

Affected Software

NameVendorStart VersionEnd Version
MysqlMysql5.0.0 (including)5.0.0 (including)
MysqlMysql5.0.1 (including)5.0.1 (including)
MysqlMysql5.0.2 (including)5.0.2 (including)
MysqlMysql5.0.3 (including)5.0.3 (including)
MysqlMysql5.0.4 (including)5.0.4 (including)
MysqlMysql5.0.5 (including)5.0.5 (including)
MysqlMysql5.0.5.0.21 (including)5.0.5.0.21 (including)
MysqlMysql5.0.10 (including)5.0.10 (including)
MysqlMysql5.0.15 (including)5.0.15 (including)
MysqlMysql5.0.16 (including)5.0.16 (including)
MysqlMysql5.0.17 (including)5.0.17 (including)
MysqlMysql5.0.20 (including)5.0.20 (including)
MysqlMysql5.0.22.1.0.1 (including)5.0.22.1.0.1 (including)
MysqlMysql5.0.24 (including)5.0.24 (including)
MysqlOracle5.0.41 (including)5.0.41 (including)
MysqlOracle5.1.1 (including)5.1.1 (including)
MysqlOracle5.1.2 (including)5.1.2 (including)
MysqlOracle5.1.10 (including)5.1.10 (including)
MysqlOracle5.1.11 (including)5.1.11 (including)
MysqlOracle5.1.12 (including)5.1.12 (including)
MysqlOracle5.1.13 (including)5.1.13 (including)
MysqlOracle5.1.14 (including)5.1.14 (including)
MysqlOracle5.1.15 (including)5.1.15 (including)
MysqlOracle5.1.16 (including)5.1.16 (including)
MysqlOracle5.1.17 (including)5.1.17 (including)
MysqlOracle6.0.0 (including)6.0.0 (including)
MysqlOracle6.0.1 (including)6.0.1 (including)
MysqlOracle6.0.2 (including)6.0.2 (including)
MysqlOracle6.0.3 (including)6.0.3 (including)
Red Hat Web Application Stack for RHEL 4RedHatmysql-0:5.0.44-2.el4s1.1*
Mysql-dfsg-5.0Ubuntudapper*
Mysql-dfsg-5.0Ubuntuedgy*
Mysql-dfsg-5.0Ubuntufeisty*
Mysql-dfsg-5.0Ubuntugutsy*
Mysql-dfsg-5.0Ubuntuupstream*

References