CVE Reference: CVE-2007-5969

NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-5969

Description:
MySQL Community Server 5.0.x before 5.0.51, Enterprise Server 5.0.x before 5.0.52, Server 5.1.x before 5.1.23, and Server 6.0.x before 6.0.4, when a table relies on symlinks created through explicit DATA DIRECTORY and INDEX DIRECTORY options, allows remote authenticated users to overwrite system table information and gain privileges via a RENAME TABLE statement that changes the symlink to point to an existing file.

CVE Status:
Candidate

References:

UBUNTU
  http://www.ubuntulinux.org/support/documentation/usn/usn-559-1

SUSE
  http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.html

ST
  1019060

SLACKWARE
  http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.428959

SAID
  Secunia Advisory: SA28025
  Secunia Advisory: SA28063
  Secunia Advisory: SA28040
  Secunia Advisory: SA27981
  Secunia Advisory: SA28108
  Secunia Advisory: SA28099
  Secunia Advisory: SA28128
  Secunia Advisory: SA28343
  Secunia Advisory: SA28559
  Secunia Advisory: SA28838
  Secunia Advisory: SA29706
  Secunia Advisory: SA32222

REDHAT
  http://www.redhat.com/support/errata/RHSA-2007-1157.html
  http://www.redhat.com/support/errata/RHSA-2007-1155.html

OVAL
  http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10509

MLIST
  http://lists.mysql.com/announce/495

MANDRIVA
  http://www.mandriva.com/security/advisories?name=MDKSA-2007:243

GENTOO
  http://security.gentoo.org/glsa/glsa-200804-04.xml

FEDORA

DEBIAN
  http://www.debian.org/security/2008/dsa-1451

CONFIRM
  http://support.apple.com/kb/HT3216
  http://forums.mysql.com/read.php?3,186931,186931
  http://dev.mysql.com/doc/refman/4.1/en/news-4-1-24.html
  http://dev.mysql.com/doc/refman/5.0/en/releasenotes-cs-5-0-51.html
  http://dev.mysql.com/doc/refman/5.0/en/releasenotes-es-5-0-52.html
  http://bugs.mysql.com/32111

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/486477/100/0/threaded

BID
  31681
  26765

APPLE
  http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html


Return to the previous page.