PT-2004-1897 · Oracle · Mysql Server

Oleksandr Byelkin

·

Published

2004-10-16

·

Updated

2019-10-07

·

CVE-2004-0835

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: MySQL versions 3.x through 3.23.58 MySQL versions 4.x through 4.0.18 MySQL versions 4.1.x through 4.1.1 MySQL versions 5.x through 5.0.0
Description: The issue allows attackers to conduct unauthorized activities by checking the CREATE/INSERT rights of the original table instead of the target table in an ALTER TABLE RENAME operation.
Recommendations: For MySQL versions 3.x through 3.23.58, update to version 3.23.59 or later. For MySQL versions 4.x through 4.0.18, update to version 4.0.19 or later. For MySQL versions 4.1.x through 4.1.1, update to version 4.1.2 or later. For MySQL versions 5.x through 5.0.0, update to version 5.0.1 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-0835
DSA-562-2

Affected Products

Mysql Server