CVE-2004-0835
MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table instead of the target table in an ALTER TABLE RENAME operation, which could allow attackers to conduct…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 22.4%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table instead of the target table in an ALTER TABLE RENAME operation, which could allow attackers to conduct unauthorized activities.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 22.35% probability · 98th percentile
- CISA KEV
- Not listed
- Affected
- mysql/mysql · oracle/mysql · debian/debian linux
- Source
- cve@mitre.org
References
- http://bugs.mysql.com/bug.php?id=3270Exploit, Vendor Advisory
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000892Broken Link
- http://lists.mysql.com/internals/13073Vendor Advisory
- http://secunia.com/advisories/12783/Patch, Vendor Advisory
- http://securitytracker.com/id?1011606Third Party Advisory, VDB Entry
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-101864-1Broken Link
- http://www.ciac.org/ciac/bulletins/p-018.shtmlBroken Link
- http://www.debian.org/security/2004/dsa-562Patch, Third Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200410-22.xmlPatch, Vendor Advisory
- http://www.mysql.org/doc/refman/4.1/en/news-4-0-19.htmlVendor Advisory
- http://www.mysql.org/doc/refman/4.1/en/news-4-1-2.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2004-597.htmlPatch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2004-611.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/11357Exploit, Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- http://www.trustix.org/errata/2004/0054/Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17666Third Party Advisory, VDB Entry
- http://bugs.mysql.com/bug.php?id=3270Exploit, Vendor Advisory
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000892Broken Link
- http://lists.mysql.com/internals/13073Vendor Advisory
- http://secunia.com/advisories/12783/Patch, Vendor Advisory
- http://securitytracker.com/id?1011606Third Party Advisory, VDB Entry
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-101864-1Broken Link
- http://www.ciac.org/ciac/bulletins/p-018.shtmlBroken Link
- http://www.debian.org/security/2004/dsa-562Patch, Third Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200410-22.xmlPatch, Vendor Advisory
- http://www.mysql.org/doc/refman/4.1/en/news-4-0-19.htmlVendor Advisory
- http://www.mysql.org/doc/refman/4.1/en/news-4-1-2.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2004-597.htmlPatch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2004-611.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/11357Exploit, Patch, Third Party Advisory, VDB Entry, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.