MySQL 4.1 before 4.1.21 and 5.0 before 5.0.24 allows a local user to access a table through a previously created MERGE table, even after the user's privileges are revoked for the original table, which might violate intended security policy.
CVSS Details
- CVSS 3.1 Base Score: 3.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Mysqlserver | — | Upgrade macOS to the latest version | Dec 16, 2011 | Aug 9, 2006 |
| Oracle_linux | — | Upgrade mysql-develUpgrade mysqlUpgrade mysql-serverUpgrade mysql-testUpgrade mysql-bench | Oct 16, 2024 | Aug 9, 2006 |
| Suse | — | Upgrade mysqlUpgrade mysql-Max | Feb 17, 2015 | Aug 9, 2006 |
| Ubuntu | — | Upgrade mysql-server-5.0 | Nov 8, 2024 | Aug 9, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub