Mandriva Linux Security Advisory – MySQL 5.0.x did not update the DEFINER value of a view when the view is altered, which allows remote authenticated users to gain privileges via a sequence of statements including a CREATE SQL SECURITY DEFINER VIEW statement and an ALTER VIEW statement. The federated engine in MySQL 5.0.x, when performing a certain SHOW TABLE STATUS query, did not properly handle a response with a small number of columns, which could allow a remote MySQL server to cause a denial of service (federated handler crash and daemon crash) via a response that lacks the minimum required number of columns.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/62826/MDVSA-2008-017.txt
Source: https://packetstormsecurity.com/files/62826/Mandriva-Linux-Security-Advisory-2008-017.html

