Bug 241690 (CVE-2007-2693) - CVE-2007-2693 An error message discloses sensitive information to user without SELECT privilege
Summary: CVE-2007-2693 An error message discloses sensitive information to user withou...
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2007-2693
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL: http://bugs.mysql.com/bug.php?id=23675
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2007-05-29 15:59 UTC by Lubomir Kundrak
Modified: 2021-11-12 19:40 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2007-06-13 12:13:37 UTC
Embargoed:


Attachments (Terms of Use)

Description Lubomir Kundrak 2007-05-29 15:59:33 UTC
Description of problem:

Certain ALTER TABLE SQL statements produce an error message that contains
information normally visible only to users with SELECT privilege.

Version-Release number of selected component (if applicable):

MySQL before 5.1.18

Comment 3 Stefan Cornelius 2007-06-13 11:51:58 UTC
are you guys sure about this? fc6 and f7 seems to ship mysql 5.0.something. the
partitions (which are important for this issue) are, afaik, actually a new
feature of 5.1.x, which is beta/unstable - so only unstable mysql 5.1 versions
prior to 5.1.18 are affected and we dodged the bullet here?

Comment 4 Lubomir Kundrak 2007-06-13 12:06:49 UTC
Stefan: thanks for the notice. I don't even know what partitioned tables are,
so I trusted what CVE read, and it was "MySQL before 5.1.18".

FC7        mysql-5.0.37-2.fc7
FC6        mysql-5.0.27-1.fc6
FC5        mysql-5.0.27-1.fc5
RHEL5      mysql-5.0.22-2.1
RHEL4      mysql-4.1.20-2.RHEL4.1
RHEL3      mysql-3.23.58-16.RHEL3.1
RHEL2.1    mysql-3.23.58-1.72.2


Note You need to log in before you can comment on or make changes to this bug.