MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table instead of the target table in an ALTER TABLE RENAME operation, which could allow attackers to conduct unauthorized activities.
https://exchange.xforce.ibmcloud.com/vulnerabilities/17666
http://www.trustix.org/errata/2004/0054/
http://www.redhat.com/support/errata/RHSA-2004-611.html
http://www.redhat.com/support/errata/RHSA-2004-597.html
http://www.mysql.org/doc/refman/4.1/en/news-4-1-2.html
http://www.mysql.org/doc/refman/4.1/en/news-4-0-19.html
http://www.gentoo.org/security/en/glsa/glsa-200410-22.xml
http://www.debian.org/security/2004/dsa-562
http://securitytracker.com/id?1011606