CVE-2007-6303
NONEMySQL 5.0.x before 5.0.51a, 5.1.x before 5.1.23, and 6.0.x before 6.0.4 does not update the DEFINER value of a view when the view is altered, which allows remote authenticated users to gain privileges
Опубликовано: 12/10/2007Обновлено: 4/9/2025
Описание
MySQL 5.0.x before 5.0.51a, 5.1.x before 5.1.23, and 6.0.x before 6.0.4 does not update the DEFINER value of a view when the view is altered, which allows remote authenticated users to gain privileges via a sequence of statements including a CREATE SQL SECURITY DEFINER VIEW statement and an ALTER VIEW statement.
ИИ-АнализНа базе ИИ
Затронутые продукты
mysqlmysql
5.0.0
mysqlmysql
5.0.1
mysqlmysql
5.0.2
mysqlmysql
5.0.3
mysqlmysql
5.0.4
mysqlmysql
5.0.5
mysqlmysql
5.0.5.0.21
mysqlmysql
5.0.10
mysqlmysql
5.0.15
mysqlmysql
5.0.16
mysqlmysql
5.0.17
mysqlmysql
5.0.20
mysqlmysql
5.0.22.1.0.1
mysqlmysql
5.0.24
oraclemysql
5.0.41
oraclemysql
5.1.1
oraclemysql
5.1.2
oraclemysql
5.1.10
oraclemysql
5.1.11
oraclemysql
5.1.12
oraclemysql
5.1.13
oraclemysql
5.1.14
oraclemysql
5.1.15
oraclemysql
5.1.16
oraclemysql
5.1.17
oraclemysql
6.0.0
oraclemysql
6.0.1
oraclemysql
6.0.2
oraclemysql
6.0.3
Ссылки
- http://bugs.mysql.com/bug.php?id=29908Exploit
- http://dev.mysql.com/doc/refman/5.0/en/releasenotes-es-5-0-52.html
- http://dev.mysql.com/doc/refman/5.1/en/news-5-1-23.html
- http://dev.mysql.com/doc/refman/6.0/en/news-6-0-4.html
- http://lists.mysql.com/announce/502
- http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.html
- http://secunia.com/advisories/28025Vendor Advisory
- http://secunia.com/advisories/28063Vendor Advisory
- http://secunia.com/advisories/28739
- http://secunia.com/advisories/28838Vendor Advisory
- http://secunia.com/advisories/29443Vendor Advisory
- http://secunia.com/advisories/29706Vendor Advisory
- http://security.gentoo.org/glsa/glsa-200804-04.xml
- http://securitytracker.com/id?1019085
- http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0040
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:017
- http://www.redhat.com/support/errata/RHSA-2007-1157.htmlVendor Advisory
- http://www.securityfocus.com/archive/1/487606/100/0/threaded
- http://www.securityfocus.com/bid/26832
- http://www.ubuntu.com/usn/usn-588-1