MySQL before 4.1.23, 5.0.x before 5.0.42, and 5.1.x before 5.1.18 does not require the DROP privilege for RENAME TABLE statements, which allows remote authenticated users to rename arbitrary tables.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
21 Nov 2024, 00:31
Type | Values Removed | Values Added |
---|---|---|
References | () http://bugs.mysql.com/bug.php?id=27515 - Vendor Advisory | |
References | () http://dev.mysql.com/doc/refman/5.1/en/news-5-1-18.html - Patch, Vendor Advisory | |
References | () http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html - Mailing List, Third Party Advisory | |
References | () http://lists.mysql.com/announce/470 - Vendor Advisory | |
References | () http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.html - Third Party Advisory | |
References | () http://osvdb.org/34766 - Broken Link | |
References | () http://secunia.com/advisories/25301 - Third Party Advisory | |
References | () http://secunia.com/advisories/25946 - Third Party Advisory | |
References | () http://secunia.com/advisories/26073 - Third Party Advisory | |
References | () http://secunia.com/advisories/26430 - Third Party Advisory | |
References | () http://secunia.com/advisories/27155 - Third Party Advisory | |
References | () http://secunia.com/advisories/27823 - Third Party Advisory | |
References | () http://secunia.com/advisories/28838 - Third Party Advisory | |
References | () http://secunia.com/advisories/30351 - Third Party Advisory | |
References | () http://secunia.com/advisories/31226 - Third Party Advisory | |
References | () http://secunia.com/advisories/32222 - Third Party Advisory | |
References | () http://support.apple.com/kb/HT3216 - Third Party Advisory | |
References | () http://www.debian.org/security/2007/dsa-1413 - Third Party Advisory | |
References | () http://www.mandriva.com/security/advisories?name=MDKSA-2007:139 - Third Party Advisory | |
References | () http://www.redhat.com/support/errata/RHSA-2007-0894.html - Third Party Advisory | |
References | () http://www.redhat.com/support/errata/RHSA-2008-0364.html - Third Party Advisory | |
References | () http://www.redhat.com/support/errata/RHSA-2008-0768.html - Third Party Advisory | |
References | () http://www.securityfocus.com/archive/1/473874/100/0/threaded - Third Party Advisory, VDB Entry | |
References | () http://www.securityfocus.com/bid/24016 - Third Party Advisory, VDB Entry | |
References | () http://www.securityfocus.com/bid/31681 - Third Party Advisory, VDB Entry | |
References | () http://www.securitytracker.com/id?1018069 - Third Party Advisory, VDB Entry | |
References | () http://www.vupen.com/english/advisories/2007/1804 - Third Party Advisory | |
References | () http://www.vupen.com/english/advisories/2008/2780 - Third Party Advisory | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/34347 - Third Party Advisory, VDB Entry | |
References | () https://issues.rpath.com/browse/RPL-1536 - Broken Link | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9559 - Third Party Advisory | |
References | () https://usn.ubuntu.com/528-1/ - Third Party Advisory |
Information
Published : 2007-05-16 01:19
Updated : 2024-11-21 00:31
NVD link : CVE-2007-2691
Mitre link : CVE-2007-2691
CVE.ORG link : CVE-2007-2691
JSON object : View
Products Affected
debian
- debian_linux
mysql
- mysql
canonical
- ubuntu_linux
CWE