>> MySQL RENAME TABLE System Table Information Overwrite Vulnerability
Title : MySQL RENAME TABLE System Table Information Overwrite Vulnerability VUPEN ID : VUPEN/ADV-2007-4142 CVE ID : CVE-2007-5969
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2007-12-10
Technical Description
A vulnerability has been identified in MySQL, which could be exploited by malicious users to bypass security restrictions. This issue is caused by an error when using RENAME TABLE against a table with explicit DATA DIRECTORY and INDEX DIRECTORY options, which could be exploited to overwrite system table information by replacing the symbolic link points.