PT-2007-4009 · Oracle+1 · Mysql Server+1

Alexander Nozdrin

·

Published

2007-05-16

·

Updated

2019-12-17

·

CVE-2007-2692

CVSS v2.0

6.0

Medium

VectorAV:N/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MySQL versions 5.0.x through 5.0.39 MySQL versions 5.1.x through 5.1.17
Description The issue allows remote authenticated users to gain privileges due to the mysql change db function not restoring THD::db access privileges when returning from SQL SECURITY INVOKER stored routines.
Recommendations For MySQL versions 5.0.x through 5.0.39, update to version 5.0.40 or later. For MySQL versions 5.1.x through 5.1.17, update to version 5.1.18 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-2692
DSA-1413-1
RHSA-2007:0894
RHSA-2008:0364
RHSA-2008_0364

Affected Products

Mysql Server
Red Hat