CVE-2007-2692
published 2007-05-16CVE-2007-2692: The mysql_change_db function in MySQL 5.0.x before 5.0.40 and 5.1.x before 5.1.18 does not restore THD::db_access privileges when returning from SQL SECURITY…
PriorityP428medium6CVSS 2.0
AVNACMAuSCPIPAP
EPSS
1.90%
77.3th percentile
The mysql_change_db function in MySQL 5.0.x before 5.0.40 and 5.1.x before 5.1.18 does not restore THD::db_access privileges when returning from SQL SECURITY INVOKER stored routines, which allows remote authenticated users to gain privileges.
Affected
48 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
CVSS provenance
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
vendor_redhat6.0MEDIUM
vendor_ubuntu3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
MySQL regression
vendor_ubuntu·2008-04-02·CVSS 3.5
CVE-2007-2692 [LOW] MySQL regression
Title: MySQL regression
Summary: MySQL regression
USN-588-1 fixed vulnerabilities in MySQL. In fixing CVE-2007-2692 for
Ubuntu 6.06, additional improvements were made to make privilege checks
more restictive. As a result, an upstream bug was exposed which could
cause operations on tables or views in a different database to fail. This
update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Masaaki Hirose discovered that MySQL could be made to dereference
a NULL pointer. An authenticated user could cause a denial of service
(application crash) via an EXPLAIN SELECT FROM on the INFORMATION_SCHEMA
table. This issue only affects Ubuntu 6.06 and 6.10. (CVE-2006-7232)
Alexander Nozdrin discovered that MySQL did not restore database access
privileges when ret
Ubuntu
MySQL vulnerabilities
vendor_ubuntu·2008-03-19·CVSS 3.5
CVE-2008-0226 [LOW] MySQL vulnerabilities
Title: MySQL vulnerabilities
Summary: MySQL vulnerabilities
Masaaki Hirose discovered that MySQL could be made to dereference
a NULL pointer. An authenticated user could cause a denial of service
(application crash) via an EXPLAIN SELECT FROM on the INFORMATION_SCHEMA
table. This issue only affects Ubuntu 6.06 and 6.10. (CVE-2006-7232)
Alexander Nozdrin discovered that MySQL did not restore database access
privileges when returning from SQL SECURITY INVOKER stored routines. An
authenticated user could exploit this to gain privileges. This issue
does not affect Ubuntu 7.10. (CVE-2007-2692)
Martin Friebe discovered that MySQL did not properly update the DEFINER
value of an altered view. An authenticated user could use CREATE SQL
SECURITY DEFINER VIEW and ALTER VIEW statements to gain pri
Red Hat
mysql SECURITY INVOKER functions do not drop privileges
vendor_redhat·2007-05-17·CVSS 6.0
CVE-2007-2692 [MEDIUM] mysql SECURITY INVOKER functions do not drop privileges
mysql SECURITY INVOKER functions do not drop privileges
The mysql_change_db function in MySQL 5.0.x before 5.0.40 and 5.1.x before 5.1.18 does not restore THD::db_access privileges when returning from SQL SECURITY INVOKER stored routines, which allows remote authenticated users to gain privileges.
Statement: This issue did not affect mysql packages as shipped in Red Hat Enterprise Linux 2.1, 3 and 4.
GHSA
GHSA-p759-pfvw-7vmx: The mysql_change_db function in MySQL 5
ghsa_unreviewed·2022-05-01
CVE-2007-2692 [MEDIUM] GHSA-p759-pfvw-7vmx: The mysql_change_db function in MySQL 5
The mysql_change_db function in MySQL 5.0.x before 5.0.40 and 5.1.x before 5.1.18 does not restore THD::db_access privileges when returning from SQL SECURITY INVOKER stored routines, which allows remote authenticated users to gain privileges.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-2691 CVE-2007-2692 CVE-2007-2693 mysql various flaws [FC6]
bugzilla·2007-06-13·CVSS 4.9
CVE-2007-2691 [MEDIUM] CVE-2007-2691 CVE-2007-2692 CVE-2007-2693 mysql various flaws [FC6]
CVE-2007-2691 CVE-2007-2692 CVE-2007-2693 mysql various flaws [FC6]
FC6 tracking bug: see blocks bug list for full details of the security issue(s).
Discussion:
FC6 has reached end of life and is no longer supported. This issue was already
fixed in currently supported versions of Fedora.
Bugzilla
CVE-2007-2691 CVE-2007-2692 CVE-2007-2693 mysql various flaws [F7]
bugzilla·2007-06-13·CVSS 4.9
CVE-2007-2691 [MEDIUM] CVE-2007-2691 CVE-2007-2692 CVE-2007-2693 mysql various flaws [F7]
CVE-2007-2691 CVE-2007-2692 CVE-2007-2693 mysql various flaws [F7]
F7 tracking bug: see blocks bug list for full details of the security issue(s).
Discussion:
This was resolved by rebased to new upstream version 5.0.45 in FEDORA-2007-1197:
https://admin.fedoraproject.org/updates/F7/FEDORA-2007-1197
Bugzilla
CVE-2007-2692 mysql SECURITY INVOKER functions do not drop privileges
bugzilla·2007-05-29·CVSS 6.0
CVE-2007-2692 [MEDIUM] CVE-2007-2692 mysql SECURITY INVOKER functions do not drop privileges
CVE-2007-2692 mysql SECURITY INVOKER functions do not drop privileges
Description of problem:
Functions declared as SECURITY INVOKER do not drop privileges upon
return and thus make it possible for an authenticated user calling
then can gain certain privileges.
Version-Release number of selected component (if applicable):
MySQL 5.0.x before 5.0.40 and 5.1.x before 5.1.18
Discussion:
This issue was addressed in:
Red Hat Application Stack:
http://rhn.redhat.com/errata/RHSA-2007-0894.html
Red Hat Enterprise Linux:
http://rhn.redhat.com/errata/RHSA-2008-0364.html
---
Reporter changed to [email protected] by request of Jay Turner.
http://bugs.mysql.com/bug.php?id=27337http://dev.mysql.com/doc/refman/5.1/en/news-5-1-18.htmlhttp://lists.mysql.com/announce/470http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.htmlhttp://osvdb.org/34765http://secunia.com/advisories/25301http://secunia.com/advisories/26073http://secunia.com/advisories/26430http://secunia.com/advisories/27823http://secunia.com/advisories/28637http://secunia.com/advisories/28838http://secunia.com/advisories/29443http://secunia.com/advisories/30351http://www.debian.org/security/2007/dsa-1413http://www.mandriva.com/security/advisories?name=MDVSA-2008:028http://www.redhat.com/support/errata/RHSA-2007-0894.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0364.htmlhttp://www.securityfocus.com/archive/1/473874/100/0/threadedhttp://www.securityfocus.com/bid/24011http://www.securitytracker.com/id?1018070http://www.ubuntu.com/usn/usn-588-1http://www.vupen.com/english/advisories/2007/1804https://exchange.xforce.ibmcloud.com/vulnerabilities/34348https://issues.rpath.com/browse/RPL-1536https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9166http://bugs.mysql.com/bug.php?id=27337http://dev.mysql.com/doc/refman/5.1/en/news-5-1-18.htmlhttp://lists.mysql.com/announce/470http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.htmlhttp://osvdb.org/34765http://secunia.com/advisories/25301http://secunia.com/advisories/26073http://secunia.com/advisories/26430http://secunia.com/advisories/27823http://secunia.com/advisories/28637http://secunia.com/advisories/28838http://secunia.com/advisories/29443http://secunia.com/advisories/30351http://www.debian.org/security/2007/dsa-1413http://www.mandriva.com/security/advisories?name=MDVSA-2008:028http://www.redhat.com/support/errata/RHSA-2007-0894.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0364.htmlhttp://www.securityfocus.com/archive/1/473874/100/0/threadedhttp://www.securityfocus.com/bid/24011http://www.securitytracker.com/id?1018070http://www.ubuntu.com/usn/usn-588-1http://www.vupen.com/english/advisories/2007/1804https://exchange.xforce.ibmcloud.com/vulnerabilities/34348https://issues.rpath.com/browse/RPL-1536https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9166
2007-05-16
Published