CVE-2007-6313: Medium severity MySQL Mysql Community Server vulnerability
Published Feb 18, 2008
·Updated
MySQL Server 5.1.x before 5.1.23 and 6.0.x before 6.0.4 does not check the rights of the entity executing BINLOG, which allows remote authorized users to execute arbitrary BINLOG statements.
Affected Software
26 affected components
MySQL Mysql Community Server=5.1.15
MySQL Mysql Community Server=5.1.19
MySQL Mysql Community Server=6.0.1
MySQL Mysql Community Server=6.0.2
MySQL Mysql Community Server=5.1.22
MySQL Mysql Community Server=5.1.1
MySQL Mysql Community Server=5.1.11
MySQL Mysql Community Server=5.1.9
MySQL Mysql Community Server=5.1.16
MySQL Mysql Community Server=6.0.0
MySQL Mysql Community Server=5.1.13
MySQL Mysql Community Server=5.1.18
MySQL Mysql Community Server=5.1.3
MySQL Mysql Community Server=5.1.12
MySQL Mysql Community Server=5.1.14
MySQL Mysql Community Server=5.1.6
MySQL Mysql Community Server=5.1.4
MySQL Mysql Community Server=5.1.20
MySQL Mysql Community Server=5.1.8
MySQL Mysql Community Server=5.1.5
MySQL Mysql Community Server=5.1.21
MySQL Mysql Community Server=5.1.10
MySQL Mysql Community Server=5.1.17
MySQL Mysql Community Server=5.1.2
MySQL Mysql Community Server=5.1.7
MySQL Mysql Community Server=6.0.3
Event History
Feb 18, 2008
CVE Published
11:00 PM
Feb 19, 2008
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-6313?
CVE-2007-6313 is rated as a high severity vulnerability because it allows remote authorized users to execute arbitrary BINLOG statements.
2
How do I fix CVE-2007-6313?
To fix CVE-2007-6313, upgrade to MySQL Server version 5.1.23 or later.
3
Which MySQL versions are affected by CVE-2007-6313?
CVE-2007-6313 affects MySQL Server 5.1.x versions prior to 5.1.23 and 6.0.x versions prior to 6.0.4.
4
Can CVE-2007-6313 be exploited remotely?
Yes, CVE-2007-6313 can be exploited by remote authorized users to execute unauthorized BINLOG statements.
5
What type of attack does CVE-2007-6313 facilitate?
CVE-2007-6313 facilitates unauthorized execution of BINLOG statements, which can lead to data corruption or information leakage.