// For flags

CVE-2007-6304

Ubuntu Security Notice 559-1

Severity Score

7.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The federated engine in MySQL 5.0.x before 5.0.51a, 5.1.x before 5.1.23, and 6.0.x before 6.0.4, when performing a certain SHOW TABLE STATUS query, allows remote MySQL servers to cause a denial of service (federated handler crash and daemon crash) via a response that lacks the minimum required number of columns.

El motor federated en MySQL versiones 5.0.x anteriores a 5.0.51a, versiones 5.1.x anteriores a 5.1.23 y versiones 6.0.x anteriores a 6.0.4, al realizar una determinada consulta SHOW TABLE STATUS, permite a los servidores MySQL remotos causar una denegación de servicio (bloqueo del manejador de federated y bloqueo del demonio) por medio de una respuesta que carece del número mínimo necesario de columnas.

Joe Gallo and Artem Russakovskii discovered that the InnoDB engine in MySQL did not properly perform input validation. An authenticated user could use a crafted CONTAINS statement to cause a denial of service. It was discovered that under certain conditions MySQL could be made to overwrite system table information. An authenticated user could use a crafted RENAME statement to escalate privileges. Philip Stoev discovered that the the federated engine of MySQL did not properly handle responses with a small number of columns. An authenticated user could use a crafted response to a SHOW TABLE STATUS query and cause a denial of service. It was discovered that MySQL did not properly enforce access controls. An authenticated user could use a crafted CREATE TABLE LIKE statement to escalate privileges.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2007-12-10 CVE Reserved
  • 2007-12-10 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-08-07 First Exploit
  • 2025-07-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
CAPEC
References (26)
URL Date SRC
http://bugs.mysql.com/bug.php?id=29801 2024-08-07
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.0
Search vendor "Mysql" for product "Mysql" and version "5.0.0"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.1
Search vendor "Mysql" for product "Mysql" and version "5.0.1"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.2
Search vendor "Mysql" for product "Mysql" and version "5.0.2"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.3
Search vendor "Mysql" for product "Mysql" and version "5.0.3"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.4
Search vendor "Mysql" for product "Mysql" and version "5.0.4"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.5
Search vendor "Mysql" for product "Mysql" and version "5.0.5"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.5.0.21
Search vendor "Mysql" for product "Mysql" and version "5.0.5.0.21"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.10
Search vendor "Mysql" for product "Mysql" and version "5.0.10"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.15
Search vendor "Mysql" for product "Mysql" and version "5.0.15"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.16
Search vendor "Mysql" for product "Mysql" and version "5.0.16"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.17
Search vendor "Mysql" for product "Mysql" and version "5.0.17"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.20
Search vendor "Mysql" for product "Mysql" and version "5.0.20"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.22.1.0.1
Search vendor "Mysql" for product "Mysql" and version "5.0.22.1.0.1"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.24
Search vendor "Mysql" for product "Mysql" and version "5.0.24"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.0
Search vendor "Oracle" for product "Mysql" and version "5.0.0"
alpha
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.3
Search vendor "Oracle" for product "Mysql" and version "5.0.3"
beta
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.6
Search vendor "Oracle" for product "Mysql" and version "5.0.6"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.7
Search vendor "Oracle" for product "Mysql" and version "5.0.7"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.8
Search vendor "Oracle" for product "Mysql" and version "5.0.8"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.9
Search vendor "Oracle" for product "Mysql" and version "5.0.9"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.11
Search vendor "Oracle" for product "Mysql" and version "5.0.11"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.12
Search vendor "Oracle" for product "Mysql" and version "5.0.12"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.13
Search vendor "Oracle" for product "Mysql" and version "5.0.13"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.14
Search vendor "Oracle" for product "Mysql" and version "5.0.14"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.18
Search vendor "Oracle" for product "Mysql" and version "5.0.18"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.19
Search vendor "Oracle" for product "Mysql" and version "5.0.19"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.21
Search vendor "Oracle" for product "Mysql" and version "5.0.21"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.22
Search vendor "Oracle" for product "Mysql" and version "5.0.22"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.27
Search vendor "Oracle" for product "Mysql" and version "5.0.27"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.33
Search vendor "Oracle" for product "Mysql" and version "5.0.33"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.37
Search vendor "Oracle" for product "Mysql" and version "5.0.37"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.41
Search vendor "Oracle" for product "Mysql" and version "5.0.41"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.1
Search vendor "Oracle" for product "Mysql" and version "5.1.1"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.2
Search vendor "Oracle" for product "Mysql" and version "5.1.2"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.10
Search vendor "Oracle" for product "Mysql" and version "5.1.10"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.11
Search vendor "Oracle" for product "Mysql" and version "5.1.11"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.12
Search vendor "Oracle" for product "Mysql" and version "5.1.12"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.13
Search vendor "Oracle" for product "Mysql" and version "5.1.13"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.14
Search vendor "Oracle" for product "Mysql" and version "5.1.14"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.15
Search vendor "Oracle" for product "Mysql" and version "5.1.15"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.16
Search vendor "Oracle" for product "Mysql" and version "5.1.16"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.17
Search vendor "Oracle" for product "Mysql" and version "5.1.17"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
6.0.0
Search vendor "Oracle" for product "Mysql" and version "6.0.0"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
6.0.1
Search vendor "Oracle" for product "Mysql" and version "6.0.1"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
6.0.2
Search vendor "Oracle" for product "Mysql" and version "6.0.2"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
6.0.3
Search vendor "Oracle" for product "Mysql" and version "6.0.3"
-
Affected