Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2007-2692

Опубликовано: 17 мая 2007
Источник: redhat

Описание

The mysql_change_db function in MySQL 5.0.x before 5.0.40 and 5.1.x before 5.1.18 does not restore THD::db_access privileges when returning from SQL SECURITY INVOKER stored routines, which allows remote authenticated users to gain privileges.

Отчет

This issue did not affect mysql packages as shipped in Red Hat Enterprise Linux 2.1, 3 and 4.

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=241689mysql SECURITY INVOKER functions do not drop privileges

Связанные уязвимости

ubuntu
больше 18 лет назад

The mysql_change_db function in MySQL 5.0.x before 5.0.40 and 5.1.x before 5.1.18 does not restore THD::db_access privileges when returning from SQL SECURITY INVOKER stored routines, which allows remote authenticated users to gain privileges.

nvd
больше 18 лет назад

The mysql_change_db function in MySQL 5.0.x before 5.0.40 and 5.1.x before 5.1.18 does not restore THD::db_access privileges when returning from SQL SECURITY INVOKER stored routines, which allows remote authenticated users to gain privileges.

debian
больше 18 лет назад

The mysql_change_db function in MySQL 5.0.x before 5.0.40 and 5.1.x be ...

github
почти 4 года назад

The mysql_change_db function in MySQL 5.0.x before 5.0.40 and 5.1.x before 5.1.18 does not restore THD::db_access privileges when returning from SQL SECURITY INVOKER stored routines, which allows remote authenticated users to gain privileges.

oracle-oval
больше 17 лет назад

ELSA-2008-0364: mysql security and bug fix update (LOW)

Уязвимость CVE-2007-2692