Computer Security
MySQL multiple security vulnerabilities
SecurityVulns ID:8064
Threat Level:
Description:CREATE TABLE LIKE privilege escalation, server crash on authentication.
Affected:ORACLE : MySQL 5.0
CVE:CVE-2007-3781 (MySQL Community Server before 5.0.45 does not require privileges such as SELECT for the source table in a CREATE TABLE LIKE statement, which allows remote authenticated users to obtain sensitive information such as the table structure.)
 CVE-2007-3780 (MySQL Community Server before 5.0.45 allows remote attackers to cause a denial of service (daemon crash) via a malformed password packet in the connection protocol.)
Original documentdocumentGENTOO, [ GLSA 200708-10 ] MySQL: Denial of Service and information leakage (17.08.2007)

