CVE-2007-5970
published 2007-12-10CVE-2007-5970: MySQL 5.1.x before 5.1.23 and 6.0.x before 6.0.4 allows remote authenticated users to gain privileges on arbitrary tables via unspecified vectors involving use…
PriorityP426medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
2.13%
79.9th percentile
MySQL 5.1.x before 5.1.23 and 6.0.x before 6.0.4 allows remote authenticated users to gain privileges on arbitrary tables via unspecified vectors involving use of table-level DATA DIRECTORY and INDEX DIRECTORY options when creating a partitioned table with the same name as a table on which the user lacks privileges.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
mysql: table privilege gain via partitioned table with the same name
vendor_redhat·2007-11-15·CVSS 5.8
CVE-2007-5970 [MEDIUM] mysql: table privilege gain via partitioned table with the same name
mysql: table privilege gain via partitioned table with the same name
MySQL 5.1.x before 5.1.23 and 6.0.x before 6.0.4 allows remote authenticated users to gain privileges on arbitrary tables via unspecified vectors involving use of table-level DATA DIRECTORY and INDEX DIRECTORY options when creating a partitioned table with the same name as a table on which the user lacks privileges.
Statement: Not vulnerable. This issue did not affect the mysql packages as shipped in Red Hat Enterprise Linux 2.1, 3, 4, 5, Red Hat Application Stack v1, and v2, as the versions shipped do not support table partitioning. The partitioning feature was introduced in development MySQL version 5.1.
GHSA
GHSA-4pw7-3p8h-fr77: MySQL 5
ghsa_unreviewed·2022-05-01
CVE-2007-5970 [MEDIUM] GHSA-4pw7-3p8h-fr77: MySQL 5
MySQL 5.1.x before 5.1.23 and 6.0.x before 6.0.4 allows remote authenticated users to gain privileges on arbitrary tables via unspecified vectors involving use of table-level DATA DIRECTORY and INDEX DIRECTORY options when creating a partitioned table with the same name as a table on which the user lacks privileges.
No detection rules found.
No public exploits indexed.
http://bugs.mysql.com/bug.php?id=32091http://dev.mysql.com/doc/refman/5.1/en/news-5-1-23.htmlhttp://dev.mysql.com/doc/refman/6.0/en/news-6-0-4.htmlhttp://osvdb.org/42607http://securitytracker.com/id?1019084http://www.vupen.com/english/advisories/2008/0560/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/38988http://bugs.mysql.com/bug.php?id=32091http://dev.mysql.com/doc/refman/5.1/en/news-5-1-23.htmlhttp://dev.mysql.com/doc/refman/6.0/en/news-6-0-4.htmlhttp://osvdb.org/42607http://securitytracker.com/id?1019084http://www.vupen.com/english/advisories/2008/0560/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/38988
2007-12-10
Published