CVE-2007-6303
published 2007-12-10CVE-2007-6303: MySQL 5.0.x before 5.0.51a, 5.1.x before 5.1.23, and 6.0.x before 6.0.4 does not update the DEFINER value of a view when the view is altered, which allows…
PriorityP418low3.5CVSS 2.0
AVNACMAuSCNIPAN
EPSS
2.23%
80.7th percentile
MySQL 5.0.x before 5.0.51a, 5.1.x before 5.1.23, and 6.0.x before 6.0.4 does not update the DEFINER value of a view when the view is altered, which allows remote authenticated users to gain privileges via a sequence of statements including a CREATE SQL SECURITY DEFINER VIEW statement and an ALTER VIEW statement.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
vendor_redhat3.5LOW
vendor_ubuntu3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w9wg-3v8p-w953: MySQL 5
ghsa_unreviewed·2022-05-01
CVE-2007-6303 [LOW] GHSA-w9wg-3v8p-w953: MySQL 5
MySQL 5.0.x before 5.0.51a, 5.1.x before 5.1.23, and 6.0.x before 6.0.4 does not update the DEFINER value of a view when the view is altered, which allows remote authenticated users to gain privileges via a sequence of statements including a CREATE SQL SECURITY DEFINER VIEW statement and an ALTER VIEW statement.
Ubuntu
MySQL regression
vendor_ubuntu·2008-04-02·CVSS 3.5
CVE-2007-2692 [LOW] MySQL regression
Title: MySQL regression
Summary: MySQL regression
USN-588-1 fixed vulnerabilities in MySQL. In fixing CVE-2007-2692 for
Ubuntu 6.06, additional improvements were made to make privilege checks
more restictive. As a result, an upstream bug was exposed which could
cause operations on tables or views in a different database to fail. This
update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Masaaki Hirose discovered that MySQL could be made to dereference
a NULL pointer. An authenticated user could cause a denial of service
(application crash) via an EXPLAIN SELECT FROM on the INFORMATION_SCHEMA
table. This issue only affects Ubuntu 6.06 and 6.10. (CVE-2006-7232)
Alexander Nozdrin discovered that MySQL did not restore database access
privileges when ret
Ubuntu
MySQL vulnerabilities
vendor_ubuntu·2008-03-19·CVSS 3.5
CVE-2008-0226 [LOW] MySQL vulnerabilities
Title: MySQL vulnerabilities
Summary: MySQL vulnerabilities
Masaaki Hirose discovered that MySQL could be made to dereference
a NULL pointer. An authenticated user could cause a denial of service
(application crash) via an EXPLAIN SELECT FROM on the INFORMATION_SCHEMA
table. This issue only affects Ubuntu 6.06 and 6.10. (CVE-2006-7232)
Alexander Nozdrin discovered that MySQL did not restore database access
privileges when returning from SQL SECURITY INVOKER stored routines. An
authenticated user could exploit this to gain privileges. This issue
does not affect Ubuntu 7.10. (CVE-2007-2692)
Martin Friebe discovered that MySQL did not properly update the DEFINER
value of an altered view. An authenticated user could use CREATE SQL
SECURITY DEFINER VIEW and ALTER VIEW statements to gain pri
Red Hat
mysql: DEFINER value of view not altered on ALTER VIEW
vendor_redhat·2007-07-19·CVSS 3.5
CVE-2007-6303 [LOW] mysql: DEFINER value of view not altered on ALTER VIEW
mysql: DEFINER value of view not altered on ALTER VIEW
MySQL 5.0.x before 5.0.51a, 5.1.x before 5.1.23, and 6.0.x before 6.0.4 does not update the DEFINER value of a view when the view is altered, which allows remote authenticated users to gain privileges via a sequence of statements including a CREATE SQL SECURITY DEFINER VIEW statement and an ALTER VIEW statement.
Statement: This issue did not affect the mysql packages as shipped in Red Hat Enterprise Linux 2.1, 3, 4, or 5.
No detection rules found.
No public exploits indexed.
http://bugs.mysql.com/bug.php?id=29908http://dev.mysql.com/doc/refman/5.0/en/releasenotes-es-5-0-52.htmlhttp://dev.mysql.com/doc/refman/5.1/en/news-5-1-23.htmlhttp://dev.mysql.com/doc/refman/6.0/en/news-6-0-4.htmlhttp://lists.mysql.com/announce/502http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.htmlhttp://secunia.com/advisories/28025http://secunia.com/advisories/28063http://secunia.com/advisories/28739http://secunia.com/advisories/28838http://secunia.com/advisories/29443http://secunia.com/advisories/29706http://security.gentoo.org/glsa/glsa-200804-04.xmlhttp://securitytracker.com/id?1019085http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0040http://www.mandriva.com/security/advisories?name=MDVSA-2008:017http://www.redhat.com/support/errata/RHSA-2007-1157.htmlhttp://www.securityfocus.com/archive/1/487606/100/0/threadedhttp://www.securityfocus.com/bid/26832http://www.ubuntu.com/usn/usn-588-1http://www.vupen.com/english/advisories/2007/4198https://exchange.xforce.ibmcloud.com/vulnerabilities/38989https://issues.rpath.com/browse/RPL-2187https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00467.htmlhttps://www.redhat.com/archives/fedora-package-announce/2007-December/msg00475.htmlhttp://bugs.mysql.com/bug.php?id=29908http://dev.mysql.com/doc/refman/5.0/en/releasenotes-es-5-0-52.htmlhttp://dev.mysql.com/doc/refman/5.1/en/news-5-1-23.htmlhttp://dev.mysql.com/doc/refman/6.0/en/news-6-0-4.htmlhttp://lists.mysql.com/announce/502http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.htmlhttp://secunia.com/advisories/28025http://secunia.com/advisories/28063http://secunia.com/advisories/28739http://secunia.com/advisories/28838http://secunia.com/advisories/29443http://secunia.com/advisories/29706http://security.gentoo.org/glsa/glsa-200804-04.xmlhttp://securitytracker.com/id?1019085http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0040http://www.mandriva.com/security/advisories?name=MDVSA-2008:017http://www.redhat.com/support/errata/RHSA-2007-1157.htmlhttp://www.securityfocus.com/archive/1/487606/100/0/threadedhttp://www.securityfocus.com/bid/26832http://www.ubuntu.com/usn/usn-588-1http://www.vupen.com/english/advisories/2007/4198https://exchange.xforce.ibmcloud.com/vulnerabilities/38989https://issues.rpath.com/browse/RPL-2187https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00467.htmlhttps://www.redhat.com/archives/fedora-package-announce/2007-December/msg00475.html
2007-12-10
Published