MySQL before 4.1.23, 5.0.x before 5.0.42, and 5.1.x before 5.1.18 does not require the DROP privilege for RENAME TABLE statements, which allows remote authenticated users to rename arbitrary tables.
References
Link Providers
http://bugs.mysql.com/bug.php?id=27515 cve-icon cve-icon
http://dev.mysql.com/doc/refman/5.1/en/news-5-1-18.html cve-icon cve-icon
http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html cve-icon cve-icon
http://lists.mysql.com/announce/470 cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.html cve-icon cve-icon
http://osvdb.org/34766 cve-icon cve-icon
http://secunia.com/advisories/25301 cve-icon cve-icon
http://secunia.com/advisories/25946 cve-icon cve-icon
http://secunia.com/advisories/26073 cve-icon cve-icon
http://secunia.com/advisories/26430 cve-icon cve-icon
http://secunia.com/advisories/27155 cve-icon cve-icon
http://secunia.com/advisories/27823 cve-icon cve-icon
http://secunia.com/advisories/28838 cve-icon cve-icon
http://secunia.com/advisories/30351 cve-icon cve-icon
http://secunia.com/advisories/31226 cve-icon cve-icon
http://secunia.com/advisories/32222 cve-icon cve-icon
http://support.apple.com/kb/HT3216 cve-icon cve-icon
http://www.debian.org/security/2007/dsa-1413 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2007:139 cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2007-0894.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2008-0364.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2008-0768.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/473874/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/24016 cve-icon cve-icon
http://www.securityfocus.com/bid/31681 cve-icon cve-icon
http://www.securitytracker.com/id?1018069 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/1804 cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/2780 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/34347 cve-icon cve-icon
https://issues.rpath.com/browse/RPL-1536 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2007-2691 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9559 cve-icon cve-icon
https://usn.ubuntu.com/528-1/ cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2007-2691 cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2007-05-16T01:00:00

Updated: 2024-08-07T13:49:57.228Z

Reserved: 2007-05-15T00:00:00

Link: CVE-2007-2691

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2007-05-16T01:19:00.000

Modified: 2018-10-19T19:00:08.020

Link: CVE-2007-2691

cve-icon Redhat

Severity : Low

Publid Date: 2007-05-17T00:00:00Z

Links: CVE-2007-2691 - Bugzilla