CVE-2007-2692

Description

From CVE.org

The mysql_change_db function in MySQL 5.0.x before 5.0.40 and 5.1.x before 5.1.18 does not restore THD::db_access privileges when returning from SQL SECURITY INVOKER stored routines, which allows remote authenticated users to gain privileges.

Statement

This issue did not affect mysql packages as shipped in Red Hat Enterprise Linux 2.1, 3 and 4.

Frequently Asked Questions

Want to get errata notifications? Sign up here.