Vulnerabilities > CVE-2007-5970 - Unspecified vulnerability in Oracle Mysql
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN oracle
nessus
Summary
MySQL 5.1.x before 5.1.23 and 6.0.x before 6.0.4 allows remote authenticated users to gain privileges on arbitrary tables via unspecified vectors involving use of table-level DATA DIRECTORY and INDEX DIRECTORY options when creating a partitioned table with the same name as a table on which the user lacks privileges.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 15 |
Nessus
NASL family | Databases |
NASL id | MYSQL_5_1_23.NASL |
description | The version of MySQL Server installed on the remote host reportedly is affected by the following issues : - It is possible, by creating a partitioned table using the DATA DIRECTORY and INDEX DIRECTORY options, to gain privileges on other tables having the same name as the partitioned table. (Bug #32091) - Using RENAME TABLE against a table with explicit DATA DIRECTORY and INDEX DIRECTORY options can be used to overwrite system table information. (Bug #32111). - ALTER VIEW retains the original DEFINER value, even when altered by another user, which can allow that user to gain the access rights of the view. (Bug #29908) - When using a FEDERATED table, the local server can be forced to crash if the remote server returns a result with fewer columns than expected. (Bug #29801) |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 29345 |
published | 2007-12-13 |
reporter | This script is Copyright (C) 2007-2018 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/29345 |
title | MySQL Community Server < 5.1.23 / 6.0.4 Multiple Vulnerabilities |
code |
|
Statements
contributor | Mark J Cox |
lastmodified | 2008-01-09 |
organization | Red Hat |
statement | Not vulnerable. This issue did not affect the mysql packages as shipped in Red Hat Enterprise Linux 2.1, 3, 4, 5, Red Hat Application Stack v1, and v2, as the versions shipped do not support table partitioning. The partitioning feature was introduced in development MySQL version 5.1. |
References
- http://bugs.mysql.com/bug.php?id=32091
- http://bugs.mysql.com/bug.php?id=32091
- http://dev.mysql.com/doc/refman/5.1/en/news-5-1-23.html
- http://dev.mysql.com/doc/refman/5.1/en/news-5-1-23.html
- http://dev.mysql.com/doc/refman/6.0/en/news-6-0-4.html
- http://dev.mysql.com/doc/refman/6.0/en/news-6-0-4.html
- http://osvdb.org/42607
- http://osvdb.org/42607
- http://securitytracker.com/id?1019084
- http://securitytracker.com/id?1019084
- http://www.vupen.com/english/advisories/2008/0560/references
- http://www.vupen.com/english/advisories/2008/0560/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38988
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38988