|Description||MySQL Community Server before 5.0.45 does not require privileges such as SELECT for the source table in a CREATE TABLE LIKE statement, which allows remote authenticated users to obtain sensitive information such as the table structure.|
|Source||CVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)|
|NVD severity||medium (attack range: remote)|
The information below is based on the following data on fixed versions.
[etch] - mysql-dfsg-5.0 <no-dsa> (Minor issue, too intrusive to backport)
[sarge] - mysql-dfsg <no-dsa> (Minor issue, too intrusive to backport)
[sarge] - mysql-dfsg-4.1 <no-dsa> (Minor issue, too intrusive to backport)