CVE-2007-2691

Publication date 16 May 2007

Last updated 24 July 2024


Ubuntu priority

MySQL before 4.1.23, 5.0.x before 5.0.42, and 5.1.x before 5.1.18 does not require the DROP privilege for RENAME TABLE statements, which allows remote authenticated users to rename arbitrary tables.

Status

Package Ubuntu Release Status
mysql-dfsg-5.0 7.04 feisty
Fixed 5.0.38-0ubuntu1.1
6.10 edgy
Fixed 5.0.24a-9ubuntu2.1
6.06 LTS dapper
Fixed 5.0.22-0ubuntu6.06.5

References

Related Ubuntu Security Notices (USN)

    • USN-528-1
    • MySQL vulnerabilities
    • 11 October 2007

Other references