CVE-2007-6303
Summary
| CVE | CVE-2007-6303 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-12-10 21:46:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | MySQL 5.0.x before 5.0.51a, 5.1.x before 5.1.23, and 6.0.x before 6.0.4 does not update the DEFINER value of a view when the view is altered, which allows remote authenticated users to gain privileges via a sequence of statements including a CREATE SQL SECURITY DEFINER VIEW statement and an ALTER VIEW statement. |
Risk And Classification
Primary CVSS: v2.0 3.5 from [email protected]
AV:N/AC:M/Au:S/C:N/I:P/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:S/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mysql | Mysql | 5.0.0 | All | All | All |
| Application | Mysql | Mysql | 5.0.1 | All | All | All |
| Application | Mysql | Mysql | 5.0.10 | All | All | All |
| Application | Mysql | Mysql | 5.0.15 | All | All | All |
| Application | Mysql | Mysql | 5.0.16 | All | All | All |
| Application | Mysql | Mysql | 5.0.17 | All | All | All |
| Application | Mysql | Mysql | 5.0.2 | All | All | All |
| Application | Mysql | Mysql | 5.0.20 | All | All | All |
| Application | Mysql | Mysql | 5.0.22.1.0.1 | All | All | All |
| Application | Mysql | Mysql | 5.0.24 | All | All | All |
| Application | Mysql | Mysql | 5.0.3 | All | All | All |
| Application | Mysql | Mysql | 5.0.4 | All | All | All |
| Application | Mysql | Mysql | 5.0.5 | All | All | All |
| Application | Mysql | Mysql | 5.0.5.0.21 | All | All | All |
| Application | Oracle | Mysql | 5.0.41 | All | All | All |
| Application | Oracle | Mysql | 5.1.1 | All | All | All |
| Application | Oracle | Mysql | 5.1.10 | All | All | All |
| Application | Oracle | Mysql | 5.1.11 | All | All | All |
| Application | Oracle | Mysql | 5.1.12 | All | All | All |
| Application | Oracle | Mysql | 5.1.13 | All | All | All |
| Application | Oracle | Mysql | 5.1.14 | All | All | All |
| Application | Oracle | Mysql | 5.1.15 | All | All | All |
| Application | Oracle | Mysql | 5.1.16 | All | All | All |
| Application | Oracle | Mysql | 5.1.17 | All | All | All |
| Application | Oracle | Mysql | 5.1.2 | All | All | All |
| Application | Oracle | Mysql | 6.0.0 | All | All | All |
| Application | Oracle | Mysql | 6.0.1 | All | All | All |
| Application | Oracle | Mysql | 6.0.2 | All | All | All |
| Application | Oracle | Mysql | 6.0.3 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Ubuntu update for mysql-dfsg-5.0 - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| issues.rpath.com/browse/RPL-2187 | af854a3a-2127-422b-91ae-364da2661108 | issues.rpath.com | |
| MySQL Security Issue and Two Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| MySQL AB :: MySQL 6.0 Reference Manual :: C.1.2 Changes in MySQL 6.0.4 (Not yet released) | af854a3a-2127-422b-91ae-364da2661108 | dev.mysql.com | |
| MySQL AB :: MySQL 5.0 Reference Manual :: C.1.3 Release Notes for MySQL Enterprise 5.0.52 [MRU] (30 Nov 2007) | af854a3a-2127-422b-91ae-364da2661108 | dev.mysql.com | |
| [security-announce] SUSE Security Summary Report SUSE-SR:2008:003 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Vendor Advisory |
| [SECURITY] Fedora 8 Update: mysql-5.0.45-6.fc8 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| rPath update for mysql - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Advisories:rPSA-2008-0040 - rPath Wiki | af854a3a-2127-422b-91ae-364da2661108 | wiki.rpath.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| MySQL Bugs: #29908: alter view keeps current definer, user can gain additioanl access | af854a3a-2127-422b-91ae-364da2661108 | bugs.mysql.com | Exploit |
| SUSE Update for Multiple Packages - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| SecurityTracker.com Archives - MySQL Bugs Let Remote Authenticated Users Gain Elevated Privileges and Deny Service | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| Gentoo Linux Documentation -- MySQL: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| MySQL Server Privilege Escalation And Denial Of Service Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Advisories | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| [SECURITY] Fedora 7 Update: mysql-5.0.45-6.fc7 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Gentoo update for mysql - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| MySQL Lists: announce: MySQL 5.0.51a has been released | af854a3a-2127-422b-91ae-364da2661108 | lists.mysql.com | |
| Fedora update for mysql - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| USN-588-1: MySQL vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| MySQL :: MySQL 5.1 Reference Manual :: C.1.9 Changes in MySQL 5.1.23 (29 January 2008) | af854a3a-2127-422b-91ae-364da2661108 | dev.mysql.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2008-01-09 | Mark J Cox | This issue did not affect the mysql packages as shipped in Red Hat Enterprise Linux 2.1, 3, 4, or 5. This issue affected the mysql packages as shipped in Red Hat Application Stack v1 and v2 and was addressed by RHSA-2007:1157: http://rhn.redhat.com/errata/RHSA-2007-1157.html |
There are currently no legacy QID mappings associated with this CVE.