FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2007-5969

This CVE name corresponds to:

Entered Topic
2009-01-11 mysql -- privilege escalation and overwrite of the system table information

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2007-5969
Phase Assigned(20071114)

Description

MySQL Community Server 5.0.x before 5.0.51, Enterprise Server 5.0.x before 5.0.52, Server 5.1.x before 5.1.23, and Server 6.0.x before 6.0.4, when a table relies on symlinks created through explicit DATA DIRECTORY and INDEX DIRECTORY options, allows remote authenticated users to overwrite system table information and gain privileges via a RENAME TABLE statement that changes the symlink to point to an existing file.

References

Source Reference
BUGTRAQ 20080117 rPSA-2008-0018-1 mysql mysql-bench mysql-server
MLIST [Announcements] 20071206 MySQL 5.0.51 has been released
CONFIRM http://bugs.mysql.com/32111
CONFIRM http://dev.mysql.com/doc/refman/5.0/en/releasenotes-cs-5-0-51.html
CONFIRM http://dev.mysql.com/doc/refman/5.0/en/releasenotes-es-5-0-52.html
CONFIRM http://forums.mysql.com/read.php?3,186931,186931
CONFIRM https://issues.rpath.com/browse/RPL-1999
CONFIRM http://dev.mysql.com/doc/refman/4.1/en/news-4-1-24.html
CONFIRM http://support.apple.com/kb/HT3216
APPLE APPLE-SA-2008-10-09
DEBIAN DSA-1451
FEDORA FEDORA-2007-4465
FEDORA FEDORA-2007-4471
GENTOO GLSA-200804-04
MANDRIVA MDKSA-2007:243
REDHAT RHSA-2007:1155
REDHAT RHSA-2007:1157
SLACKWARE SSA:2007-348-01
SUSE SUSE-SR:2008:003
UBUNTU USN-559-1
BID 26765
BID 31681
OVAL oval:org.mitre.oval:def:10509
VUPEN ADV-2007-4142
VUPEN ADV-2007-4198
VUPEN ADV-2008-0560
VUPEN ADV-2008-1000
VUPEN ADV-2008-2780
SECTRACK 1019060
SECUNIA 27981
SECUNIA 28040
SECUNIA 28063
SECUNIA 28025
SECUNIA 28108
SECUNIA 28099
SECUNIA 28128
SECUNIA 28343
SECUNIA 28559
SECUNIA 28838
SECUNIA 29706
SECUNIA 32222