Name | CVE-2007-5969 |
Description | MySQL Community Server 5.0.x before 5.0.51, Enterprise Server 5.0.x before 5.0.52, Server 5.1.x before 5.1.23, and Server 6.0.x before 6.0.4, when a table relies on symlinks created through explicit DATA DIRECTORY and INDEX DIRECTORY options, allows remote authenticated users to overwrite system table information and gain privileges via a RENAME TABLE statement that changes the symlink to point to an existing file. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DSA-1451-1 |
Debian Bugs | 455010 |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
mysql-dfsg-4.1 | source | (unstable) | (unfixed) | |||
mysql-dfsg-5.0 | source | etch | 5.0.32-7etch4 | DSA-1451-1 | ||
mysql-dfsg-5.0 | source | (unstable) | 5.0.45-4 | low | 455010 |