FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2004-0835

This CVE name corresponds to:

Entered Topic
2004-12-16 mysql -- erroneous access restrictions applied to table renames

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2004-0835
Phase Assigned(20040908)

Description

MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table instead of the target table in an ALTER TABLE RENAME operation, which could allow attackers to conduct unauthorized activities.

References

Source Reference
CONFIRM http://www.mysql.org/doc/refman/4.1/en/news-4-0-19.html
CONFIRM http://www.mysql.org/doc/refman/4.1/en/news-4-1-2.html
CONECTIVA CLA-2004:892
DEBIAN DSA-562
GENTOO GLSA-200410-22
REDHAT RHSA-2004:597
REDHAT RHSA-2004:611
SUNALERT 101864
TRUSTIX 2004-0054
MISC http://bugs.mysql.com/bug.php?id=3270
MISC http://lists.mysql.com/internals/13073
CIAC P-018
SECUNIA 12783
SECTRACK 1011606
BID 11357
XF mysql-alter-restriction-bypass(17666)