CVE-2007-3781
Publication date 15 July 2007
Last updated 24 July 2024
Ubuntu priority
Description
MySQL Community Server before 5.0.45 does not require privileges such as SELECT for the source table in a CREATE TABLE LIKE statement, which allows remote authenticated users to obtain sensitive information such as the table structure.
Notes
jdstrand
very invasive patch. Discussed one-time MicroVersionUpdate with pitti-- too many changes to warrant the update. apparently Mandriva found a patch for this going back to 5.0.24
References
Related Ubuntu Security Notices (USN)
- USN-559-1
- MySQL vulnerabilities
- 21 December 2007