SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |    Help    |   

SecurityTracker
Archives


Your Ad Here
 
Click to Sign Up
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com

Sign Up!





Category:  Application (Database)  >  MySQL Vendors:  MySQL.com
MySQL MERGE Access Control Error May Let Users Access a Restricted Table
SecurityTracker Alert ID:  1016617
SecurityTracker URL:  http://securitytracker.com/id?1016617
CVE Reference:  CVE-2006-4031   (Links to External Site)
Updated:  Jun 8 2008
Original Entry Date:  Aug 1 2006
Impact:  Disclosure of user information, Modification of user information
Fix Available:  Yes   Vendor Confirmed:  Yes  
Version(s): 4.x prior to 4.1.21; 5.0 prior to 5.0.24
Description:  A vulnerability was reported in MySQL. A remote authenticated user can continue to access a table after their privileges have been revoked.

A remote authenticated user with access to a MyISAM table can create a MERGE table that accesses the original table. If the user's privileges for the original table are subsequently revoked, the user can still access the original table via the new table.

The original report is available at:

http://bugs.mysql.com/bug.php?id=15195

Peter Gulutzan reported this vulnerability.

Impact:  A remote authenticated user may be able to access a table after the user's privileges for that table have been revoked.
Solution:  The vendor has released fixed versions (4.1.21, 5.0.24).

The MySQL advisory is available at:

http://dev.mysql.com/doc/refman/4.1/en/news-4-1-21.html
http://dev.mysql.com/doc/refman/5.0/en/news-5-0-24.html

Vendor URL:  www.mysql.com/products/mysql/ (Links to External Site)
Cause:  Access control error
Underlying OS:  Linux (Any), UNIX (Any), Windows (Any)

Message History:   None.


 Source Message Contents

Date:  Tue, 1 Aug 2006 14:10:06 -0400
Subject:  MySQL

 
 
http://dev.mysql.com/doc/refman/4.1/en/news-4-1-21.html
http://dev.mysql.com/doc/refman/5.0/en/news-5-0-24.html
 
Security fix: If a user has access to MyISAM table t, that user can create a MERGE 
table m that accesses t. However, if the user's privileges on t are subsequently 
revoked, the user can continue to access t by doing so through m. If this behavior is 
undesirable, you can start the server with the new --skip-merge option to disable the 
MERGE storage engine. (Bug#15195)
 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us   |    Help

Copyright 2007, SecurityGlobal.net LLC