CVE-2007-5969
Last modified
CVE-2007-5969 is a vulnerability of currently unknown severity. MySQL Community Server 5.0.x before 5.0.51, Enterprise Server 5.0.x before 5.0.52, Server 5.1.x before 5.1.23, and Server 6.0.x before 6.0.4, when a table relies on symlinks created through explicit DATA DIRECTORY and INDEX DIRECTORY options, allows remote authenticated users to overwrite system table information and gain privileges via a RENAME TABLE statement that changes the symlink to point to an existing file.. EPSS estimates a 14.26% chance of exploitation in the next 30 days.
Description
MySQL Community Server 5.0.x before 5.0.51, Enterprise Server 5.0.x before 5.0.52, Server 5.1.x before 5.1.23, and Server 6.0.x before 6.0.4, when a table relies on symlinks created through explicit DATA DIRECTORY and INDEX DIRECTORY options, allows remote authenticated users to overwrite system table information and gain privileges via a RENAME TABLE statement that changes the symlink to point to an existing file.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mysql | Mysql Server | 5.1.22 |
| Mysql | Mysql Server | 6.0 |
| Mysql | Mysql Server | 6.0.1 |
| Mysql | Mysql Server | 6.0.2 |
| Mysql | Mysql Server | 6.0.3 |
| Mysql | Community Server | <= 5.0.50 |
| Mysql | Community Server | 5.0.41 |
| Mysql | Community Server | 5.0.44 |
| Mysql | Community Server | 5.0.45 |
| Mysql | Mysql Enterprise Server | 5.0.50 |
References
- http://lists.mysql.com/announce/495Exploit, Vendor Advisory
- http://secunia.com/advisories/27981Vendor Advisory
- http://secunia.com/advisories/28025Vendor Advisory
- http://secunia.com/advisories/28040Vendor Advisory
- http://secunia.com/advisories/28063Vendor Advisory
- http://secunia.com/advisories/28099Vendor Advisory
- http://secunia.com/advisories/28108Vendor Advisory
- http://secunia.com/advisories/28128Vendor Advisory
- http://secunia.com/advisories/28343Vendor Advisory
- http://secunia.com/advisories/28559Vendor Advisory
- http://secunia.com/advisories/28838Vendor Advisory
- http://secunia.com/advisories/29706Vendor Advisory
- http://secunia.com/advisories/32222Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2007-1155.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2007-1157.htmlVendor Advisory
- http://www.vupen.com/english/advisories/2007/4142Vendor Advisory
- http://www.vupen.com/english/advisories/2007/4198Vendor Advisory
- http://www.vupen.com/english/advisories/2008/0560/referencesVendor Advisory
- http://www.vupen.com/english/advisories/2008/1000/referencesVendor Advisory
- http://www.vupen.com/english/advisories/2008/2780Vendor Advisory
- http://lists.mysql.com/announce/495Exploit, Vendor Advisory
- http://secunia.com/advisories/27981Vendor Advisory
- http://secunia.com/advisories/28025Vendor Advisory
- http://secunia.com/advisories/28040Vendor Advisory
- http://secunia.com/advisories/28063Vendor Advisory
- http://secunia.com/advisories/28099Vendor Advisory
- http://secunia.com/advisories/28108Vendor Advisory
- http://secunia.com/advisories/28128Vendor Advisory
- http://secunia.com/advisories/28343Vendor Advisory
- http://secunia.com/advisories/28559Vendor Advisory
- http://secunia.com/advisories/28838Vendor Advisory
- http://secunia.com/advisories/29706Vendor Advisory
- http://secunia.com/advisories/32222Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2007-1155.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2007-1157.htmlVendor Advisory
- http://www.vupen.com/english/advisories/2007/4142Vendor Advisory
- http://www.vupen.com/english/advisories/2007/4198Vendor Advisory
- http://www.vupen.com/english/advisories/2008/0560/referencesVendor Advisory
- http://www.vupen.com/english/advisories/2008/1000/referencesVendor Advisory
- http://www.vupen.com/english/advisories/2008/2780Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-5969?
How severe is CVE-2007-5969?
How do I fix CVE-2007-5969?
Are you affected by CVE-2007-5969?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
