MySQL Community Server before 5.0.45 does not require privileges such as SELECT for the source table in a CREATE TABLE LIKE statement, which allows remote authenticated users to obtain sensitive information such as the table structure.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade dev-db/mysql. | Oct 30, 2017 | Jul 15, 2007 |
| Oracle_linux | — | Upgrade mysqlUpgrade mysql-benchUpgrade mysql-testUpgrade mysql-serverUpgrade mysql-devel | Oct 16, 2024 | Jul 15, 2007 |
| Suse | — | Upgrade mysql-debugUpgrade mysql-shared-32bitUpgrade mysqlUpgrade mysql-develUpgrade mysql-shared-64bitUpgrade mysql-sharedUpgrade suse-releaseUpgrade mysql-MaxUpgrade mysql-clientUpgrade mysql-bench | Dec 12, 2013 | Jul 15, 2007 |
| Ubuntu | — | Upgrade mysql-server-5.0 | Nov 8, 2024 | Jul 15, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub