mysql: possible system table information overwrite using symlinks
Published Dec 10, 2007
7.1
HIGHCVSS 2.0
EPSS 14.26%
Description
MySQL Community Server 5.0.x before 5.0.51, Enterprise Server 5.0.x before 5.0.52, Server 5.1.x before 5.1.23, and Server 6.0.x before 6.0.4, when a table relies on symlinks created through explicit DATA DIRECTORY and INDEX DIRECTORY options, allows remote authenticated users to overwrite system table information and gain privileges via a RENAME TABLE statement that changes the symlink to point to an existing file.
Affected products
No data.
Configuration 1
- 5.1.22
- 6.0
- 6.0.1
- 6.0.2
- 6.0.3
Configuration 2
- ≤ 5.0.50
- 5.0.41
- 5.0.44
- 5.0.45
Configuration 3
- 5.0.50
No data.
Red Hat Enterprise Linux 4
mysql-0:4.1.20-3.RHEL4.1.el4_6.1
Fixed · RHSA-2007:1155
Red Hat Enterprise Linux 5
mysql-0:5.0.22-2.2.el5_1.1
Fixed · RHSA-2007:1155
Red Hat Web Application Stack for RHEL 4
mysql-0:5.0.44-2.el4s1.1
Fixed · RHSA-2007:1157
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 4 | mysql-0:4.1.20-3.RHEL4.1.el4_6.1 | Fixed | RHSA-2007:1155 |
| Red Hat Enterprise Linux 5 | mysql-0:5.0.22-2.2.el5_1.1 | Fixed | RHSA-2007:1155 |
| Red Hat Web Application Stack for RHEL 4 | mysql-0:5.0.44-2.el4s1.1 | Fixed | RHSA-2007:1157 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:H/Au:S/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (14 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 14.26% (0.14260) | 96.49th | v5 (v2026.06.15) |
| Jun 15, 2026 | 14.26% (0.14260) | 96.13th | v5 (v2026.06.15) |
| Mar 30, 2025 | 1.70% (0.01705) | 80.63th | v4 (v2025.03.14) |
| Mar 29, 2025 | 3.66% (0.03661) | 79.55th | v4 (v2025.03.14) |
| Mar 17, 2025 | 1.70% (0.01705) | 81.08th | v4 (v2025.03.14) |
| Dec 28, 2024 | 7.24% (0.07239) | 93.96th | v3 (v2023.03.01) |
| Nov 20, 2024 | 3.95% (0.03953) | 92.30th | v3 (v2023.03.01) |
| May 13, 2024 | 2.82% (0.02823) | 90.62th | v3 (v2023.03.01) |
| Dec 16, 2023 | 2.01% (0.02010) | 87.63th | v3 (v2023.03.01) |
| Nov 8, 2023 | 1.86% (0.01860) | 86.98th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.92% (0.00917) | 80.43th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.53% (0.02528) | 81.92th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.53% (0.02528) | 80.15th | v2 (v2022.01.01) |
| Feb 4, 2022 | 2.53% (0.02528) | 58.66th | v2 (v2022.01.01) |
References (45)
- http://bugs.mysql.com/32111 x_refsource_CONFIRM
- http://dev.mysql.com/doc/refman/4.1/en/news-4-1-24.html x_refsource_CONFIRM
- http://dev.mysql.com/doc/refman/5.0/en/releasenotes-cs-5-0-51.html x_refsource_CONFIRM
- http://dev.mysql.com/doc/refman/5.0/en/releasenotes-es-5-0-52.html x_refsource_CONFIRM
- http://forums.mysql.com/read.php?3%2C186931%2C186931 x_refsource_CONFIRM
- http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html vendor-advisoryx_refsource_APPLE
- http://lists.mysql.com/announce/495 mailing-listx_refsource_MLISTExploitVendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.html vendor-advisoryx_refsource_SUSE
- http://secunia.com/advisories/27981 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/28025 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/28040 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/28063 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/28099 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/28108 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/28128 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/28343 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/28559 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/28838 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/29706 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/32222 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://security.gentoo.org/glsa/glsa-200804-04.xml vendor-advisoryx_refsource_GENTOO
- http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.428959 vendor-advisoryx_refsource_SLACKWARE
- http://support.apple.com/kb/HT3216 x_refsource_CONFIRM
- http://www.debian.org/security/2008/dsa-1451 vendor-advisoryx_refsource_DEBIAN
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:243 vendor-advisoryx_refsource_MANDRIVA
- http://www.redhat.com/support/errata/RHSA-2007-1155.html vendor-advisoryx_refsource_REDHATVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2007-1157.html vendor-advisoryx_refsource_REDHATVendor Advisory
- http://www.securityfocus.com/archive/1/486477/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/26765 vdb-entryx_refsource_BID
- http://www.securityfocus.com/bid/31681 vdb-entryx_refsource_BIDPatch
- http://www.securitytracker.com/id?1019060 vdb-entryx_refsource_SECTRACK
- http://www.vupen.com/english/advisories/2007/4142 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2007/4198 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2008/0560/references vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2008/1000/references vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2008/2780 vdb-entryx_refsource_VUPENVendor Advisory
- https://access.redhat.com/security/cve/CVE-2007-5969 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=397071 Issue Tracking
- https://issues.rpath.com/browse/RPL-1999 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2007-5969
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10509 vdb-entrysignaturex_refsource_OVAL
- https://usn.ubuntu.com/559-1/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2007-5969
- https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00467.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00475.html vendor-advisoryx_refsource_FEDORA
Change history (0)
No recorded changes yet.