CVE-2007-2693
published 2007-05-16CVE-2007-2693: MySQL before 5.1.18 allows remote authenticated users without SELECT privileges to obtain sensitive information from partitioned tables via an ALTER TABLE…
PriorityP410low3.5CVSS 2.0
AVNACMAuSCPINAN
EPSS
1.79%
75.8th percentile
MySQL before 5.1.18 allows remote authenticated users without SELECT privileges to obtain sensitive information from partitioned tables via an ALTER TABLE statement.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mysql | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:P/I:N/A:N
vendor_redhat3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
An error message discloses sensitive information to user without SELECT privilege
vendor_redhat·2007-05-17·CVSS 3.5
CVE-2007-2693 [LOW] An error message discloses sensitive information to user without SELECT privilege
An error message discloses sensitive information to user without SELECT privilege
MySQL before 5.1.18 allows remote authenticated users without SELECT privileges to obtain sensitive information from partitioned tables via an ALTER TABLE statement.
Statement: Not vulnerable. These issues did not affect the versions of mysql as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5.
GHSA
GHSA-3jwg-934c-hf4r: MySQL before 5
ghsa_unreviewed·2022-05-01
CVE-2007-2693 [LOW] GHSA-3jwg-934c-hf4r: MySQL before 5
MySQL before 5.1.18 allows remote authenticated users without SELECT privileges to obtain sensitive information from partitioned tables via an ALTER TABLE statement.
No detection rules found.
Bugzilla
CVE-2007-2691 CVE-2007-2692 CVE-2007-2693 mysql various flaws [FC6]
bugzilla·2007-06-13·CVSS 4.9
CVE-2007-2691 [MEDIUM] CVE-2007-2691 CVE-2007-2692 CVE-2007-2693 mysql various flaws [FC6]
CVE-2007-2691 CVE-2007-2692 CVE-2007-2693 mysql various flaws [FC6]
FC6 tracking bug: see blocks bug list for full details of the security issue(s).
Discussion:
FC6 has reached end of life and is no longer supported. This issue was already
fixed in currently supported versions of Fedora.
Bugzilla
CVE-2007-2691 CVE-2007-2692 CVE-2007-2693 mysql various flaws [F7]
bugzilla·2007-06-13·CVSS 4.9
CVE-2007-2691 [MEDIUM] CVE-2007-2691 CVE-2007-2692 CVE-2007-2693 mysql various flaws [F7]
CVE-2007-2691 CVE-2007-2692 CVE-2007-2693 mysql various flaws [F7]
F7 tracking bug: see blocks bug list for full details of the security issue(s).
Discussion:
This was resolved by rebased to new upstream version 5.0.45 in FEDORA-2007-1197:
https://admin.fedoraproject.org/updates/F7/FEDORA-2007-1197
Bugzilla
CVE-2007-2693 An error message discloses sensitive information to user without SELECT privilege
bugzilla·2007-05-29·CVSS 3.5
CVE-2007-2693 [LOW] CVE-2007-2693 An error message discloses sensitive information to user without SELECT privilege
CVE-2007-2693 An error message discloses sensitive information to user without SELECT privilege
Description of problem:
Certain ALTER TABLE SQL statements produce an error message that contains
information normally visible only to users with SELECT privilege.
Version-Release number of selected component (if applicable):
MySQL before 5.1.18
Discussion:
are you guys sure about this? fc6 and f7 seems to ship mysql 5.0.something. the
partitions (which are important for this issue) are, afaik, actually a new
feature of 5.1.x, which is beta/unstable - so only unstable mysql 5.1 versions
prior to 5.1.18 are affected and we dodged the bullet here?
---
Stefan: thanks for the notice. I don't even know what partitioned tables are,
so I trusted what CVE read, and it was "MySQL before 5.1.18".
http://bugs.mysql.com/bug.php?id=23675http://dev.mysql.com/doc/refman/5.1/en/news-5-1-18.htmlhttp://secunia.com/advisories/25301http://www.securityfocus.com/bid/24008http://www.securitytracker.com/id?1018071http://www.vupen.com/english/advisories/2007/1804https://exchange.xforce.ibmcloud.com/vulnerabilities/34349http://bugs.mysql.com/bug.php?id=23675http://dev.mysql.com/doc/refman/5.1/en/news-5-1-18.htmlhttp://secunia.com/advisories/25301http://www.securityfocus.com/bid/24008http://www.securitytracker.com/id?1018071http://www.vupen.com/english/advisories/2007/1804https://exchange.xforce.ibmcloud.com/vulnerabilities/34349
2007-05-16
Published