CVE-2007-5969

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

MySQL Community Server 5.0.x before 5.0.51, Enterprise Server 5.0.x before 5.0.52, Server 5.1.x before 5.1.23, and Server 6.0.x before 6.0.4, when a table relies on symlinks created through explicit DATA DIRECTORY and INDEX DIRECTORY options, allows remote authenticated users to overwrite system table information and gain privileges via a RENAME TABLE statement that changes the symlink to point to an existing file.

References

http://bugs.mysql.com/32111

http://dev.mysql.com/doc/refman/4.1/en/news-4-1-24.html

http://dev.mysql.com/doc/refman/5.0/en/releasenotes-cs-5-0-51.html

http://dev.mysql.com/doc/refman/5.0/en/releasenotes-es-5-0-52.html

http://forums.mysql.com/read.php?3,186931,186931

http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html

http://lists.mysql.com/announce/495

http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.html

http://secunia.com/advisories/27981

http://secunia.com/advisories/28025

http://secunia.com/advisories/28040

http://secunia.com/advisories/28063

http://secunia.com/advisories/28099

http://secunia.com/advisories/28108

http://secunia.com/advisories/28128

http://secunia.com/advisories/28343

http://secunia.com/advisories/28559

http://secunia.com/advisories/28838

http://secunia.com/advisories/29706

http://secunia.com/advisories/32222

http://security.gentoo.org/glsa/glsa-200804-04.xml

http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.428959

http://support.apple.com/kb/HT3216

http://www.debian.org/security/2008/dsa-1451

http://www.mandriva.com/security/advisories?name=MDKSA-2007:243

http://www.redhat.com/support/errata/RHSA-2007-1155.html

http://www.redhat.com/support/errata/RHSA-2007-1157.html

http://www.securityfocus.com/archive/1/486477/100/0/threaded

http://www.securityfocus.com/bid/26765

http://www.securityfocus.com/bid/31681

http://www.securitytracker.com/id?1019060

http://www.vupen.com/english/advisories/2007/4142

http://www.vupen.com/english/advisories/2007/4198

http://www.vupen.com/english/advisories/2008/0560/references

http://www.vupen.com/english/advisories/2008/1000/references

http://www.vupen.com/english/advisories/2008/2780

https://issues.rpath.com/browse/RPL-1999

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10509

https://usn.ubuntu.com/559-1/

https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00467.html

https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00475.html

Details

Source: MITRE

Published: 2007-12-10

Updated: 2018-10-15

Type: CWE-264

Risk Information

CVSS v2

Base Score: 7.1

Vector: AV:N/AC:H/Au:S/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 3.9

Severity: HIGH

Tenable Plugins

View all (27 total)

IDNameProductFamilySeverity
78218F5 Networks BIG-IP : MySQL vulnerabilities (SOL8178)NessusF5 Networks Local Security Checks
high
67624Oracle Linux 4 / 5 : mysql (ELSA-2007-1155)NessusOracle Linux Local Security Checks
high
60332Scientific Linux Security Update : mysql on SL5.x, SL4.x i386/x86_64NessusScientific Linux Local Security Checks
high
41184SuSE9 Security Update : MySQL (YOU Patch Number 12044)NessusSuSE Local Security Checks
high
35339FreeBSD : mysql -- privilege escalation and overwrite of the system table information (8c451386-dff3-11dd-a765-0030843d3802)NessusFreeBSD Local Security Checks
high
34374Mac OS X Multiple Vulnerabilities (Security Update 2008-007)NessusMacOS X Local Security Checks
critical
34159MySQL Community Server 5.0 < 5.0.67 Multiple VulnerabilitiesNessusDatabases
high
31835GLSA-200804-04 : MySQL: Multiple vulnerabilitiesNessusGentoo Local Security Checks
high
30182SuSE 10 Security Update : MySQL (ZYPP Patch Number 4879)NessusSuSE Local Security Checks
high
30180openSUSE 10 Security Update : libmysqlclient-devel (libmysqlclient-devel-4873)NessusSuSE Local Security Checks
high
29860Debian DSA-1451-1 : mysql-dfsg-5.0 - several vulnerabilitiesNessusDebian Local Security Checks
high
29793Ubuntu 6.06 LTS / 6.10 / 7.04 / 7.10 : mysql-dfsg-5.0 vulnerabilities (USN-559-1)NessusUbuntu Local Security Checks
high
29752CentOS 4 : mysql (CESA-2007:1222-001)NessusCentOS Local Security Checks
high
29737RHEL 4 / 5 : mysql (RHSA-2007:1155)NessusRed Hat Local Security Checks
high
29731CentOS 4 / 5 : mysql (CESA-2007:1155)NessusCentOS Local Security Checks
high
29714Fedora 7 : mysql-5.0.45-6.fc7 (2007-4471)NessusFedora Local Security Checks
high
29712Fedora 8 : mysql-5.0.45-6.fc8 (2007-4465)NessusFedora Local Security Checks
high
29704Slackware 11.0 / 12.0 / current : mysql (SSA:2007-348-01)NessusSlackware Local Security Checks
high
4313MySQL Community Server < 5.1.23 / 6.0.4 Multiple VulnerabilitiesNessus Network MonitorDatabase
medium
4312Oracle MySQL Enterprise Server < 5.0.52 Multiple VulnerabilitiesNessus Network MonitorDatabase
medium
29346MySQL Enterprise Server 5.0 < 5.0.52 Multiple VulnerabilitiesNessusDatabases
medium
29345MySQL Community Server < 5.1.23 / 6.0.4 Multiple VulnerabilitiesNessusDatabases
medium
29300Mandrake Linux Security Advisory : MySQL (MDKSA-2007:243)NessusMandriva Local Security Checks
high
29251MySQL Community Server 5.0 < 5.0.51 RENAME TABLE Symlink System Table OverwriteNessusDatabases
high
4309Oracle MySQL < 5.0.51 RENAME TABLE Symlink System Table OverwriteNessus Network MonitorDatabase
high
801147MySQL Community Server < 5.1.23 / 6.0.4 Multiple VulnerabilitiesLog Correlation EngineDatabase
medium
801138MySQL Enterprise Server < 5.0.52 Multiple VulnerabilitiesLog Correlation EngineDatabase
medium