MySQL Table View Access Bug Lets Remote Authenticated Users Gain Elevated Privileges
|
|
SecurityTracker Alert ID: 1018663
|
|
SecurityTracker URL: http://securitytracker.com/id?1018663
|
|
CVE Reference: CVE-2007-3782
(Links to External Site)
|
Date: Sep 7 2007
|
Impact: User access via network
|
Fix Available: Yes
Exploit Included: Yes
Vendor Confirmed: Yes
|
Version(s): prior to 5.0.45
|
Description: A vulnerability was reported in MySQL. A remote authenticated user can gain elevated privileges on a different database.
A remote authenticated user can use a view that refers to an external table of a different database to gain update privileges for that table.
Phil Anderton reported this vulnerability.
|
Impact: A remote authenticated user can gain update privileges for a table in another database on the target system.
|
Solution: The vendor has issued a fixed version (5.0.45).
|
Vendor URL: bugs.mysql.com/bug.php?id=27878 (Links to External Site)
|
Cause: Access control error
|
Underlying OS: Linux (Any), UNIX (Any), Windows (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Fri, 7 Sep 2007 01:01:59 -0400
Subject: MySQL
|
http://bugs.mysql.com/bug.php?id=27878
CVE-2007-3782
|
|