First published: Mon Dec 10 2007(Updated: )
MySQL Community Server 5.0.x before 5.0.51, Enterprise Server 5.0.x before 5.0.52, Server 5.1.x before 5.1.23, and Server 6.0.x before 6.0.4, when a table relies on symlinks created through explicit DATA DIRECTORY and INDEX DIRECTORY options, allows remote authenticated users to overwrite system table information and gain privileges via a RENAME TABLE statement that changes the symlink to point to an existing file.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mysql Mysql Server | =6.0 | |
Mysql Mysql Server | =6.0.3 | |
Mysql Mysql Server | =6.0.1 | |
Mysql Mysql Server | =5.1.22 | |
Mysql Mysql Server | =6.0.2 | |
MySQL Community Server | =5.0.45 | |
MySQL Community Server | =5.0.41 | |
MySQL Community Server | =5.0.44 | |
MySQL Community Server | <=5.0.50 | |
Mysql Mysql Enterprise Server | =5.0.50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.