Back to search
CVE-2007-6303
Published: Dec 10, 2007
Modified: Aug 7, 2024
PUBLISHED
Description
MySQL 5.0.x before 5.0.51a, 5.1.x before 5.1.23, and 6.0.x before 6.0.4 does not update the DEFINER value of a view when the view is altered, which allows remote authenticated users to gain privileges via a sequence of statements including a CREATE SQL SECURITY DEFINER VIEW statement and an ALTER VIEW statement.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0040
x_refsource_CONFIRM
http://lists.mysql.com/announce/502
x_refsource_CONFIRM
GLSA-200804-04
vendor-advisory
x_refsource_GENTOO
29706
third-party-advisory
x_refsource_SECUNIA
mysql-definer-value-privilege-escalation(38989)
vdb-entry
x_refsource_XF
29443
third-party-advisory
x_refsource_SECUNIA
MDVSA-2008:017
vendor-advisory
x_refsource_MANDRIVA
https://issues.rpath.com/browse/RPL-2187
x_refsource_CONFIRM
FEDORA-2007-4465
vendor-advisory
x_refsource_FEDORA
RHSA-2007:1157
vendor-advisory
x_refsource_REDHAT
http://dev.mysql.com/doc/refman/5.1/en/news-5-1-23.html
x_refsource_CONFIRM
ADV-2007-4198
vdb-entry
x_refsource_VUPEN
FEDORA-2007-4471
vendor-advisory
x_refsource_FEDORA
http://dev.mysql.com/doc/refman/5.0/en/releasenotes-es-5-0-52.html
x_refsource_CONFIRM
http://bugs.mysql.com/bug.php?id=29908
x_refsource_CONFIRM
26832
vdb-entry
x_refsource_BID
1019085
vdb-entry
x_refsource_SECTRACK
28025
third-party-advisory
x_refsource_SECUNIA
http://dev.mysql.com/doc/refman/6.0/en/news-6-0-4.html
x_refsource_CONFIRM
20080205 rPSA-2008-0040-1 mysql mysql-bench mysql-server
mailing-list
x_refsource_BUGTRAQ
28838
third-party-advisory
x_refsource_SECUNIA
USN-588-1
vendor-advisory
x_refsource_UBUNTU
28063
third-party-advisory
x_refsource_SECUNIA
SUSE-SR:2008:003
vendor-advisory
x_refsource_SUSE
28739
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now