Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2007-2692

Publication date 16 May 2007

Last updated 24 July 2024


Ubuntu priority

The mysql_change_db function in MySQL 5.0.x before 5.0.40 and 5.1.x before 5.1.18 does not restore THD::db_access privileges when returning from SQL SECURITY INVOKER stored routines, which allows remote authenticated users to gain privileges.

Read the notes from the security team

Status

Package Ubuntu Release Status
mysql-dfsg-5.0 7.10 gutsy
Fixed 5.0.45-1ubuntu2
7.04 feisty
Fixed 5.0.38-0ubuntu1.4
6.10 edgy
Fixed 5.0.24a-9ubuntu2.4
6.06 LTS dapper
Fixed 5.0.22-0ubuntu6.06.8

Notes


jdstrand

very large complicated patch that requires many changes to the source and does not apply cleanly at all to feisty's 5.0.38, let alone to edgy and dapper. Trying to backport this fix would more than likely cause larger problems than not fixing it. Currently discussing a one-time MicroVersionUpdate option. May have to "wont-fix" and give an updated pacakge in -backports. per pitti et al, too many changes for a MicroVersionUpdate patch now in etch (5.0.32-7etch3), but causes several test cases to fail on dapper through feisty (TODO: test etch) etch patch left out both the test cases and patch to sql/sql_db.cc. If add the test cases then etch fails

References

Related Ubuntu Security Notices (USN)

    • USN-588-1
    • MySQL vulnerabilities
    • 19 March 2008

Other references