CVE-2007-2691
published 2007-05-16CVE-2007-2691: MySQL before 4.1.23, 5.0.x before 5.0.42, and 5.1.x before 5.1.18 does not require the DROP privilege for RENAME TABLE statements, which allows remote…
PriorityP425medium4.9CVSS 2.0
AVNACMAuSCNIPAP
EPSS
2.85%
85.3th percentile
MySQL before 4.1.23, 5.0.x before 5.0.42, and 5.1.x before 5.1.18 does not require the DROP privilege for RENAME TABLE statements, which allows remote authenticated users to rename arbitrary tables.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| mysql | mysql | <= 4.1.22 | — |
| mysql | mysql | >= 5.0 < 5.0.42 | 5.0.42 |
| mysql | mysql | >= 5.1 < 5.1.18 | 5.1.18 |
CVSS provenance
nvdv2.04.9MEDIUMAV:N/AC:M/Au:S/C:N/I:P/A:P
vendor_redhat4.9MEDIUM
vendor_ubuntu4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
MySQL vulnerabilities
vendor_ubuntu·2007-10-11·CVSS 4.0
CVE-2007-3782 [MEDIUM] MySQL vulnerabilities
Title: MySQL vulnerabilities
Summary: MySQL vulnerabilities
Neil Kettle discovered that MySQL could be made to dereference a NULL
pointer and divide by zero. An authenticated user could exploit this
with a crafted IF clause, leading to a denial of service. (CVE-2007-2583)
Victoria Reznichenko discovered that MySQL did not always require the
DROP privilege. An authenticated user could exploit this via RENAME
TABLE statements to rename arbitrary tables, possibly gaining additional
database access. (CVE-2007-2691)
It was discovered that MySQL could be made to overflow a signed char
during authentication. Remote attackers could use crafted authentication
requests to cause a denial of service. (CVE-2007-3780)
Phil Anderton discovered that MySQL did not properly verify access
privileges whe
Red Hat
mysql DROP privilege not enforced when renaming tables
vendor_redhat·2007-05-17·CVSS 4.9
CVE-2007-2691 [MEDIUM] mysql DROP privilege not enforced when renaming tables
mysql DROP privilege not enforced when renaming tables
MySQL before 4.1.23, 5.0.x before 5.0.42, and 5.1.x before 5.1.18 does not require the DROP privilege for RENAME TABLE statements, which allows remote authenticated users to rename arbitrary tables.
GHSA
GHSA-2xc6-gj77-5g2j: MySQL before 4
ghsa_unreviewed·2022-05-01
CVE-2007-2691 [MEDIUM] GHSA-2xc6-gj77-5g2j: MySQL before 4
MySQL before 4.1.23, 5.0.x before 5.0.42, and 5.1.x before 5.1.18 does not require the DROP privilege for RENAME TABLE statements, which allows remote authenticated users to rename arbitrary tables.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-2691 CVE-2007-2692 CVE-2007-2693 mysql various flaws [FC6]
bugzilla·2007-06-13·CVSS 4.9
CVE-2007-2691 [MEDIUM] CVE-2007-2691 CVE-2007-2692 CVE-2007-2693 mysql various flaws [FC6]
CVE-2007-2691 CVE-2007-2692 CVE-2007-2693 mysql various flaws [FC6]
FC6 tracking bug: see blocks bug list for full details of the security issue(s).
Discussion:
FC6 has reached end of life and is no longer supported. This issue was already
fixed in currently supported versions of Fedora.
Bugzilla
CVE-2007-2691 CVE-2007-2692 CVE-2007-2693 mysql various flaws [F7]
bugzilla·2007-06-13·CVSS 4.9
CVE-2007-2691 [MEDIUM] CVE-2007-2691 CVE-2007-2692 CVE-2007-2693 mysql various flaws [F7]
CVE-2007-2691 CVE-2007-2692 CVE-2007-2693 mysql various flaws [F7]
F7 tracking bug: see blocks bug list for full details of the security issue(s).
Discussion:
This was resolved by rebased to new upstream version 5.0.45 in FEDORA-2007-1197:
https://admin.fedoraproject.org/updates/F7/FEDORA-2007-1197
Bugzilla
CVE-2007-2691 mysql DROP privilege not enforced when renaming tables
bugzilla·2007-05-29·CVSS 4.9
CVE-2007-2691 [MEDIUM] CVE-2007-2691 mysql DROP privilege not enforced when renaming tables
CVE-2007-2691 mysql DROP privilege not enforced when renaming tables
Description of problem:
Contrary to what the documentation says, ALTER privilege on the old table
and CREATE and INSERT privileges on the new table are sufficient for the
user to be able to rename a table.
Version-Release number of selected component (if applicable):
MySQL before 4.1.23, 5.0.x before 5.0.42, and 5.1.x before 5.1.18.
Discussion:
Upstream bug report: http://bugs.mysql.com/bug.php?id=27515
---
Reporter changed to [email protected] by request of Jay Turner.
---
This issue has been addressed in following products:
Red Hat Linux Enterprise 4
Red Hat Linux Enterprise 5
Red Hat Application Stack v1 for Enterprise Linux AS/ES (v.4)
Via
https://rhn.redhat.com/errata/RHSA-2008-0768.html
h
http://bugs.mysql.com/bug.php?id=27515http://dev.mysql.com/doc/refman/5.1/en/news-5-1-18.htmlhttp://lists.apple.com/archives/security-announce/2008/Oct/msg00001.htmlhttp://lists.mysql.com/announce/470http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.htmlhttp://osvdb.org/34766http://secunia.com/advisories/25301http://secunia.com/advisories/25946http://secunia.com/advisories/26073http://secunia.com/advisories/26430http://secunia.com/advisories/27155http://secunia.com/advisories/27823http://secunia.com/advisories/28838http://secunia.com/advisories/30351http://secunia.com/advisories/31226http://secunia.com/advisories/32222http://support.apple.com/kb/HT3216http://www.debian.org/security/2007/dsa-1413http://www.mandriva.com/security/advisories?name=MDKSA-2007:139http://www.redhat.com/support/errata/RHSA-2007-0894.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0364.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0768.htmlhttp://www.securityfocus.com/archive/1/473874/100/0/threadedhttp://www.securityfocus.com/bid/24016http://www.securityfocus.com/bid/31681http://www.securitytracker.com/id?1018069http://www.vupen.com/english/advisories/2007/1804http://www.vupen.com/english/advisories/2008/2780https://exchange.xforce.ibmcloud.com/vulnerabilities/34347https://issues.rpath.com/browse/RPL-1536https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9559https://usn.ubuntu.com/528-1/http://bugs.mysql.com/bug.php?id=27515http://dev.mysql.com/doc/refman/5.1/en/news-5-1-18.htmlhttp://lists.apple.com/archives/security-announce/2008/Oct/msg00001.htmlhttp://lists.mysql.com/announce/470http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.htmlhttp://osvdb.org/34766http://secunia.com/advisories/25301http://secunia.com/advisories/25946http://secunia.com/advisories/26073http://secunia.com/advisories/26430http://secunia.com/advisories/27155http://secunia.com/advisories/27823http://secunia.com/advisories/28838http://secunia.com/advisories/30351http://secunia.com/advisories/31226http://secunia.com/advisories/32222http://support.apple.com/kb/HT3216http://www.debian.org/security/2007/dsa-1413http://www.mandriva.com/security/advisories?name=MDKSA-2007:139http://www.redhat.com/support/errata/RHSA-2007-0894.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0364.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0768.htmlhttp://www.securityfocus.com/archive/1/473874/100/0/threadedhttp://www.securityfocus.com/bid/24016http://www.securityfocus.com/bid/31681http://www.securitytracker.com/id?1018069http://www.vupen.com/english/advisories/2007/1804http://www.vupen.com/english/advisories/2008/2780https://exchange.xforce.ibmcloud.com/vulnerabilities/34347https://issues.rpath.com/browse/RPL-1536https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9559https://usn.ubuntu.com/528-1/
2007-05-16
Published