First published: Mon Feb 18 2008(Updated: )
MySQL Server 5.1.x before 5.1.23 and 6.0.x before 6.0.4 does not check the rights of the entity executing BINLOG, which allows remote authorized users to execute arbitrary BINLOG statements.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MySQL Community Server | =5.1.15 | |
MySQL Community Server | =5.1.19 | |
MySQL Community Server | =6.0.1 | |
MySQL Community Server | =6.0.2 | |
MySQL Community Server | =5.1.22 | |
MySQL Community Server | =5.1.1 | |
MySQL Community Server | =5.1.11 | |
MySQL Community Server | =5.1.9 | |
MySQL Community Server | =5.1.16 | |
MySQL Community Server | =6.0.0 | |
MySQL Community Server | =5.1.13 | |
MySQL Community Server | =5.1.18 | |
MySQL Community Server | =5.1.3 | |
MySQL Community Server | =5.1.12 | |
MySQL Community Server | =5.1.14 | |
MySQL Community Server | =5.1.6 | |
MySQL Community Server | =5.1.4 | |
MySQL Community Server | =5.1.20 | |
MySQL Community Server | =5.1.8 | |
MySQL Community Server | =5.1.5 | |
MySQL Community Server | =5.1.21 | |
MySQL Community Server | =5.1.10 | |
MySQL Community Server | =5.1.17 | |
MySQL Community Server | =5.1.2 | |
MySQL Community Server | =5.1.7 | |
MySQL Community Server | =6.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-6313 is rated as a high severity vulnerability because it allows remote authorized users to execute arbitrary BINLOG statements.
To fix CVE-2007-6313, upgrade to MySQL Server version 5.1.23 or later.
CVE-2007-6313 affects MySQL Server 5.1.x versions prior to 5.1.23 and 6.0.x versions prior to 6.0.4.
Yes, CVE-2007-6313 can be exploited by remote authorized users to execute unauthorized BINLOG statements.
CVE-2007-6313 facilitates unauthorized execution of BINLOG statements, which can lead to data corruption or information leakage.