National Vulnerability Database

National Vulnerability Database

National Vulnerability
Database

CVE-2007-6303 Detail

Current Description

MySQL 5.0.x before 5.0.51a, 5.1.x before 5.1.23, and 6.0.x before 6.0.4 does not update the DEFINER value of a view when the view is altered, which allows remote authenticated users to gain privileges via a sequence of statements including a CREATE SQL SECURITY DEFINER VIEW statement and an ALTER VIEW statement.

Source:  MITRE      Last Modified:  12/10/2007      View Analysis Description

Quick Info

CVE Dictionary Entry:
CVE-2007-6303
Original release date:
12/10/2007
Last revised:
08/07/2017
Source:
US-CERT/NIST

Impact

CVSS Severity (version 2.0):
CVSS v2 Base Score:
3.5 LOW
Vector:
(AV:N/AC:M/Au:S/C:N/I:P/A:N) (legend)
Impact Subscore:
2.9
Exploitability Subscore:
6.8
CVSS Version 2 Metrics:
Access Vector:
Network exploitable
Access Complexity:
Medium
Authentication:
Required to exploit
Impact Type:
Allows unauthorized modification

Vendor Statements (disclaimer)

Official Statement from Red Hat (01/09/2008)

This issue did not affect the mysql packages as shipped in Red Hat Enterprise Linux 2.1, 3, 4, or 5. This issue affected the mysql packages as shipped in Red Hat Application Stack v1 and v2 and was addressed by RHSA-2007:1157: http://rhn.redhat.com/errata/RHSA-2007-1157.html

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to nvd@nist.gov.

Hyperlink Resource Type Source Name
http://bugs.mysql.com/bug.php?id=29908 Exploit External Source CONFIRM http://bugs.mysql.com/bug.php?id=29908
http://dev.mysql.com/doc/refman/5.0/en/releasenotes-es-5-0-52.html External Source CONFIRM http://dev.mysql.com/doc/refman/5.0/en/releasenotes-es-5-0-52.html
http://dev.mysql.com/doc/refman/5.1/en/news-5-1-23.html External Source CONFIRM http://dev.mysql.com/doc/refman/5.1/en/news-5-1-23.html
http://dev.mysql.com/doc/refman/6.0/en/news-6-0-4.html External Source CONFIRM http://dev.mysql.com/doc/refman/6.0/en/news-6-0-4.html
http://lists.mysql.com/announce/502 External Source CONFIRM http://lists.mysql.com/announce/502
http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.html External Source SUSE SUSE-SR:2008:003
http://security.gentoo.org/glsa/glsa-200804-04.xml External Source GENTOO GLSA-200804-04
http://securitytracker.com/id?1019085 External Source SECTRACK 1019085
http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0040 External Source CONFIRM http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0040
http://www.mandriva.com/security/advisories?name=MDVSA-2008:017 External Source MANDRIVA MDVSA-2008:017
http://www.redhat.com/support/errata/RHSA-2007-1157.html Vendor Advisory External Source REDHAT RHSA-2007:1157
http://www.securityfocus.com/archive/1/archive/1/487606/100/0/threaded External Source BUGTRAQ 20080205 rPSA-2008-0040-1 mysql mysql-bench mysql-server
http://www.securityfocus.com/bid/26832 External Source BID 26832
http://www.ubuntu.com/usn/usn-588-1 External Source UBUNTU USN-588-1
http://www.vupen.com/english/advisories/2007/4198 Vendor Advisory External Source VUPEN ADV-2007-4198
https://exchange.xforce.ibmcloud.com/vulnerabilities/38989 External Source XF mysql-definer-value-privilege-escalation(38989)
https://issues.rpath.com/browse/RPL-2187 External Source CONFIRM https://issues.rpath.com/browse/RPL-2187
https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00467.html External Source FEDORA FEDORA-2007-4465
https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00475.html External Source FEDORA FEDORA-2007-4471

Technical Details

Vulnerability Type (View All)

Vulnerable software and versions Switch to CPE 2.2

Configuration 1
OR
cpe:2.3:a:mysql:mysql:5.0:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.0:alpha:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.1a:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.3:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.3:beta:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.3a:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.4:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.4a:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.5:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.5.0.21:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.6:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.7:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.8:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.9:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.10:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.10a:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.11:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.12:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.13:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.14:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.15:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.15a:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.16:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.16a:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.17:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.17a:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.18:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.19:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.20:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.20a:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.21:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.22:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.22.1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.24:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.27:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.33:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.37:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.0.41:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.1.1:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.1.2:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.1.10:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.1.11:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.1.12:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.1.13:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.1.14:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.1.15:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.1.16:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:5.1.17:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:6.0.0:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:6.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:6.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mysql:mysql:6.0.3:*:*:*:*:*:*:*

Denotes Vulnerable Software
Are we missing a CPE here? Please let us know.

Change History 2 change records found - show changes