MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table instead of the target table in an ALTER TABLE RENAME operation, which could allow attackers to conduct unauthorized activities.
References
Configurations
History
20 Nov 2024, 23:49
Type | Values Removed | Values Added |
---|---|---|
References | () http://bugs.mysql.com/bug.php?id=3270 - Exploit, Vendor Advisory | |
References | () http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000892 - Broken Link | |
References | () http://lists.mysql.com/internals/13073 - Vendor Advisory | |
References | () http://secunia.com/advisories/12783/ - Patch, Vendor Advisory | |
References | () http://securitytracker.com/id?1011606 - Third Party Advisory, VDB Entry | |
References | () http://sunsolve.sun.com/search/document.do?assetkey=1-26-101864-1 - Broken Link | |
References | () http://www.ciac.org/ciac/bulletins/p-018.shtml - Broken Link | |
References | () http://www.debian.org/security/2004/dsa-562 - Patch, Third Party Advisory | |
References | () http://www.gentoo.org/security/en/glsa/glsa-200410-22.xml - Patch, Vendor Advisory | |
References | () http://www.mysql.org/doc/refman/4.1/en/news-4-0-19.html - Vendor Advisory | |
References | () http://www.mysql.org/doc/refman/4.1/en/news-4-1-2.html - Vendor Advisory | |
References | () http://www.redhat.com/support/errata/RHSA-2004-597.html - Patch, Vendor Advisory | |
References | () http://www.redhat.com/support/errata/RHSA-2004-611.html - Patch, Vendor Advisory | |
References | () http://www.securityfocus.com/bid/11357 - Exploit, Patch, Third Party Advisory, VDB Entry, Vendor Advisory | |
References | () http://www.trustix.org/errata/2004/0054/ - Vendor Advisory | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/17666 - Third Party Advisory, VDB Entry |
Information
Published : 2004-11-03 05:00
Updated : 2024-11-20 23:49
NVD link : CVE-2004-0835
Mitre link : CVE-2004-0835
CVE.ORG link : CVE-2004-0835
JSON object : View
Products Affected
debian
- debian_linux
mysql
- mysql
oracle
- mysql
CWE