CVE-2007-3782
Summary
| CVE | CVE-2007-3782 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-07-15 22:30:00 UTC |
| Updated | 2018-10-15 21:30:00 UTC |
| Description | MySQL Community Server before 5.0.45 allows remote authenticated users to gain update privileges for a table in another database via a view that refers to this external table. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| MySQL Denial of Service Vulnerability and Multiple Security Issues - Advisories - Secunia |
SECUNIA |
secunia.com |
|
| rPath update for mysql, mysql-bench, and mysql-server - Advisories - Secunia |
SECUNIA |
secunia.com |
|
| SecurityFocus |
BUGTRAQ |
www.securityfocus.com |
|
| MySQL AB :: MySQL 5.0 Reference Manual :: D.1.2 Release Notes for MySQL Community Server 5.0.45 (04 July 2007) |
CONFIRM |
dev.mysql.com |
|
| SUSE Update for Multiple Packages - Advisories - Secunia |
SECUNIA |
secunia.com |
|
| MySQL Bugs: #27878: Use of view overrides column update privileges on underlying table |
CONFIRM |
bugs.mysql.com |
|
| Security Announcement |
SUSE |
www.novell.com |
|
| Debian update for mysql-dfsg, mysql-dfsg-5.0, and mysql-dfsg-4.1 - Advisories - Secunia |
SECUNIA |
secunia.com |
|
| Support |
REDHAT |
www.redhat.com |
|
| Red Hat update for mysql - Advisories - Secunia |
SECUNIA |
secunia.com |
|
| Ubuntu update for mysql - Advisories - Secunia |
SECUNIA |
secunia.com |
|
| USN-528-1: MySQL vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
|
| rhn.redhat.com | Red Hat Support |
REDHAT |
www.redhat.com |
|
| issues.rpath.com/browse/RPL-1536 |
CONFIRM |
issues.rpath.com |
|
| MySQL Lists: announce: MySQL Community Server 5.0.45 has been released! |
MLIST |
lists.mysql.com |
|
| Advisories - Mandriva Linux |
MANDRIVA |
www.mandriva.com |
|
| MySQL Table View Access Bug Lets Remote Authenticated Users Gain Elevated Privileges - SecurityTracker |
SECTRACK |
securitytracker.com |
|
| Mandriva update for mysql - Advisories - Secunia |
SECUNIA |
secunia.com |
|
| MySQL Access Validation and Denial of Service Vulnerabilities |
BID |
www.securityfocus.com |
|
| Debian -- Security Information -- DSA-1413-1 mysql |
DEBIAN |
www.debian.org |
|
| Repository / Oval Repository |
OVAL |
oval.cisecurity.org |
|
| rPath update for mysql, mysql-bench, and mysql-server - Advisories - Secunia |
SECUNIA |
secunia.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|
| Red Hat | 2007-07-17 | Mark J Cox | Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=248553 The Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw. |
There are currently no legacy QID mappings associated with this CVE.