Computer Security
[EN] securityvulns.ru no-pyccku


MySQL multiple security vulnerabilities
Published:13.10.2007
Source:
SecurityVulns ID:8248
Type:remote
Threat Level:
6/10
Description:Denial of service, privilege escalation.
Affected:MYSQL : MySQL 4.1
 ORACLE : MySQL 5.0
CVE:CVE-2007-3782 (MySQL Community Server before 5.0.45 allows remote authenticated users to gain update privileges for a table in another database via a view that refers to this external table.)
 CVE-2007-3780 (MySQL Community Server before 5.0.45 allows remote attackers to cause a denial of service (daemon crash) via a malformed password packet in the connection protocol.)
 CVE-2007-2691 (MySQL before 4.1.23, 5.0.x before 5.0.42, and 5.1.x before 5.1.18 does not require the DROP privilege for RENAME TABLE statements, which allows remote authenticated users to rename arbitrary tables.)
 CVE-2007-2583 (The in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40, and 5.1 before 5.1.18-beta, allows context-dependent attackers to cause a denial of service (crash) via a crafted IF clause that results in a divide-by-zero error and a NULL pointer dereference.)
Original documentdocumentUBUNTU, bugtraq@securityfocus.com, full-disclosure@lists.grok.org.uk (13.10.2007)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod