CVE-2007-2691

Updated on 16 May 2007

Severity

Awaiting Analysis

Details

Overview

About vulnerability

MySQL before 4.1.23, 5.0.x before 5.0.42, and 5.1.x before 5.1.18 does not require the DROP privilege for RENAME TABLE statements, which allows remote authenticated users to rename arbitrary tables.

Details

Affected packages:
hive-hcatalog-core @ 2.3.9 (+537 more)
MySQL before 4.1.23, 5.0.x before 5.0.42, and 5.1.x before 5.1.18 does not require the DROP privilege for RENAME TABLE statements, which allows remote authenticated users to rename arbitrary tables.