CVE-2007-6303

Impact:
Low
Public Date:
2007-07-19
Bugzilla:
420231: CVE-2007-6303 mysql: DEFINER value of view not altered on ALTER VIEW

The MITRE CVE dictionary describes this issue as:

MySQL 5.0.x before 5.0.51a, 5.1.x before 5.1.23, and 6.0.x before 6.0.4 does not update the DEFINER value of a view when the view is altered, which allows remote authenticated users to gain privileges via a sequence of statements including a CREATE SQL SECURITY DEFINER VIEW statement and an ALTER VIEW statement.

Find out more about CVE-2007-6303 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

This issue did not affect the mysql packages as shipped in Red Hat Enterprise Linux 2.1, 3, 4, or 5.

This issue affected the mysql packages as shipped in Red Hat Application Stack v1 and v2 and was addressed by RHSA-2007:1157:
http://rhn.redhat.com/errata/RHSA-2007-1157.html

Red Hat Security Errata

Platform Errata Release Date
Red Hat Application Stack v2 for Enterprise Linux (v.5) (mysql) RHSA-2007:1157 2007-12-19
Red Hat Application Stack v1 for Enterprise Linux AS (v.4) (mysql) RHSA-2007:1157 2007-12-19

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.