This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Mysql First view 2007-12-10
Product Mysql Server Last view 2012-05-03
Version Type
Update  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:a:mysql:mysql_server:5.1.22:*:*:*:*:*:*:* 2
cpe:2.3:a:mysql:mysql_server:6.0.3:*:*:*:*:*:*:* 1
cpe:2.3:a:mysql:mysql_server:6.0:*:*:*:*:*:*:* 1
cpe:2.3:a:mysql:mysql_server:6.0.1:*:*:*:*:*:*:* 1
cpe:2.3:a:mysql:mysql_server:6.0.2:*:*:*:*:*:*:* 1

Related : CVE

  Date Alert Description
4 2012-05-03 CVE-2012-1696

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.19 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.

7.1 2007-12-10 CVE-2007-5969

MySQL Community Server 5.0.x before 5.0.51, Enterprise Server 5.0.x before 5.0.52, Server 5.1.x before 5.1.23, and Server 6.0.x before 6.0.4, when a table relies on symlinks created through explicit DATA DIRECTORY and INDEX DIRECTORY options, allows remote authenticated users to overwrite system table information and gain privileges via a RENAME TABLE statement that changes the symlink to point to an existing file.

CWE : Common Weakness Enumeration

%idName
100% (1) CWE-264 Permissions, Privileges, and Access Controls

Oval Markup Language : Definitions

OvalID Name
oval:org.mitre.oval:def:10509 MySQL Community Server 5.0.x before 5.0.51, Enterprise Server 5.0.x before 5....

Open Source Vulnerability Database (OSVDB)

id Description
42608 MySQL RENAME TABLE Symlink System Table Overwrite

OpenVAS Exploits

id Description
2010-05-12 Name : Mac OS X Security Update 2008-007
File : nvt/macosx_secupd_2008-007.nasl
2009-10-10 Name : SLES9: Security update for MySQL
File : nvt/sles9p5021882.nasl
2009-04-09 Name : Mandriva Update for MySQL MDKSA-2007:243 (MySQL)
File : nvt/gb_mandriva_MDKSA_2007_243.nasl
2009-03-23 Name : Ubuntu Update for mysql-dfsg-5.0 vulnerabilities USN-559-1
File : nvt/gb_ubuntu_USN_559_1.nasl
2009-03-06 Name : RedHat Update for mysql RHSA-2007:1155-01
File : nvt/gb_RHSA-2007_1155-01_mysql.nasl
2009-02-27 Name : CentOS Update for mysql CESA-2007:1155 centos4 i386
File : nvt/gb_CESA-2007_1155_mysql_centos4_i386.nasl
2009-02-27 Name : CentOS Update for mysql CESA-2007:1155 centos4 x86_64
File : nvt/gb_CESA-2007_1155_mysql_centos4_x86_64.nasl
2009-02-27 Name : Fedora Update for mysql FEDORA-2007-4465
File : nvt/gb_fedora_2007_4465_mysql_fc8.nasl
2009-02-27 Name : Fedora Update for mysql FEDORA-2007-4471
File : nvt/gb_fedora_2007_4471_mysql_fc7.nasl
2009-01-13 Name : FreeBSD Ports: mysql-server
File : nvt/freebsd_mysql-server17.nasl
2008-09-24 Name : Gentoo Security Advisory GLSA 200804-04 (mysql)
File : nvt/glsa_200804_04.nasl
2008-01-17 Name : Debian Security Advisory DSA 1451-1 (mysql-dfsg-5.0)
File : nvt/deb_1451_1.nasl
0000-00-00 Name : Slackware Advisory SSA:2007-348-01 mysql
File : nvt/esoft_slk_ssa_2007_348_01.nasl

Nessus® Vulnerability Scanner

id Description
2014-10-10 Name: The remote device is missing a vendor-supplied security patch.
File: f5_bigip_SOL8178.nasl - Type: ACT_GATHER_INFO
2014-06-13 Name: The remote openSUSE host is missing a security update.
File: openSUSE-2012-276.nasl - Type: ACT_GATHER_INFO
2014-06-13 Name: The remote openSUSE host is missing a security update.
File: openSUSE-2012-273.nasl - Type: ACT_GATHER_INFO
2013-08-30 Name: The remote Gentoo host is missing one or more security-related patches.
File: gentoo_GLSA-201308-06.nasl - Type: ACT_GATHER_INFO
2013-07-12 Name: The remote Oracle Linux host is missing one or more security updates.
File: oraclelinux_ELSA-2007-1155.nasl - Type: ACT_GATHER_INFO
2012-08-01 Name: The remote Scientific Linux host is missing one or more security updates.
File: sl_20071218_mysql_on_SL5_x.nasl - Type: ACT_GATHER_INFO
2012-01-19 Name: The remote database server is affected by multiple vulnerabilities.
File: mysql_5_5_20.nasl - Type: ACT_GATHER_INFO
2009-09-24 Name: The remote SuSE 9 host is missing a security-related patch.
File: suse9_12044.nasl - Type: ACT_GATHER_INFO
2009-01-12 Name: The remote FreeBSD host is missing one or more security-related updates.
File: freebsd_pkg_8c451386dff311dda7650030843d3802.nasl - Type: ACT_GATHER_INFO
2008-10-10 Name: The remote host is missing a Mac OS X update that fixes various security issues.
File: macosx_SecUpd2008-007.nasl - Type: ACT_GATHER_INFO
2008-09-11 Name: The remote database server is affected by several issues.
File: mysql_5_0_67.nasl - Type: ACT_GATHER_INFO
2008-04-11 Name: The remote Gentoo host is missing one or more security-related patches.
File: gentoo_GLSA-200804-04.nasl - Type: ACT_GATHER_INFO
2008-02-05 Name: The remote SuSE 10 host is missing a security-related patch.
File: suse_mysql-4879.nasl - Type: ACT_GATHER_INFO
2008-02-05 Name: The remote openSUSE host is missing a security update.
File: suse_libmysqlclient-devel-4873.nasl - Type: ACT_GATHER_INFO
2008-01-07 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-1451.nasl - Type: ACT_GATHER_INFO
2007-12-24 Name: The remote Ubuntu host is missing one or more security-related patches.
File: ubuntu_USN-559-1.nasl - Type: ACT_GATHER_INFO
2007-12-19 Name: The remote CentOS host is missing one or more security updates.
File: centos_RHSA-2007-1155.nasl - Type: ACT_GATHER_INFO
2007-12-19 Name: The remote Red Hat host is missing one or more security updates.
File: redhat-RHSA-2007-1155.nasl - Type: ACT_GATHER_INFO
2007-12-17 Name: The remote Fedora host is missing a security update.
File: fedora_2007-4471.nasl - Type: ACT_GATHER_INFO
2007-12-17 Name: The remote Fedora host is missing a security update.
File: fedora_2007-4465.nasl - Type: ACT_GATHER_INFO
2007-12-17 Name: The remote Slackware host is missing a security update.
File: Slackware_SSA_2007-348-01.nasl - Type: ACT_GATHER_INFO
2007-12-13 Name: The remote database server is affected by several issues.
File: mysql_enterprise_5_0_52.nasl - Type: ACT_GATHER_INFO
2007-12-13 Name: The remote database server is affected by several issues.
File: mysql_5_1_23.nasl - Type: ACT_GATHER_INFO
2007-12-11 Name: The remote Mandrake Linux host is missing one or more security updates.
File: mandrake_MDKSA-2007-243.nasl - Type: ACT_GATHER_INFO
2007-12-10 Name: The remote database server is susceptible to a local symlink attack.
File: mysql_5_0_51.nasl - Type: ACT_GATHER_INFO