PublicDate: 2007-12-10 19:46:00 UTC Candidate: CVE-2007-5969 References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5969 https://rhn.redhat.com/errata/RHSA-2007-1155.html https://ubuntu.com/security/notices/USN-559-1 Description: MySQL Community Server 5.0.x before 5.0.51, Enterprise Server 5.0.x before 5.0.52, Server 5.1.x before 5.1.23, and Server 6.0.x before 6.0.4, when a table relies on symlinks created through explicit DATA DIRECTORY and INDEX DIRECTORY options, allows remote authenticated users to overwrite system table information and gain privileges via a RENAME TABLE statement that changes the symlink to point to an existing file. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: upstream_mysql-dfsg-5.0: released (5.0.45-4) dapper_mysql-dfsg-5.0: released (5.0.22-0ubuntu6.06.6) edgy_mysql-dfsg-5.0: released (5.0.24a-9ubuntu2.2) feisty_mysql-dfsg-5.0: released (5.0.38-0ubuntu1.2) gutsy_mysql-dfsg-5.0: released (5.0.45-1ubuntu3.1) devel_mysql-dfsg-5.0: not-affected (5.0.51a-1ubuntu1)