MySQL before 5.1.18 allows remote authenticated users without SELECT privileges to obtain sensitive information from partitioned tables via an ALTER TABLE statement.
| Software | From | Fixed in |
|---|---|---|
| mysql / mysql | 5.1.5 | 5.1.5.x |
| oracle / mysql | 5.1.6 | 5.1.6.x |
| oracle / mysql | 5.1.9 | 5.1.9.x |
| oracle / mysql | 5.1.10 | 5.1.10.x |
| oracle / mysql | 5.1.11 | 5.1.11.x |
| oracle / mysql | 5.1.12 | 5.1.12.x |
| oracle / mysql | 5.1.13 | 5.1.13.x |
| oracle / mysql | 5.1.14 | 5.1.14.x |
| oracle / mysql | 5.1.15 | 5.1.15.x |
| oracle / mysql | 5.1.16 | 5.1.16.x |
| oracle / mysql | 5.1.17 | 5.1.17.x |