CVE-2006-4227
Summary
| CVE | CVE-2006-4227 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-08-18 20:04:00 UTC |
| Updated | 2019-12-17 20:05:00 UTC |
| Description | MySQL before 5.0.25 and 5.1 before 5.1.12 evaluates arguments of suid routines in the security context of the routine's definer instead of the routine's caller, which allows remote authenticated users to gain privileges through a routine that has been made available using GRANT EXECUTE. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| MySQL Create Database Bypass and Privilege Escalation - Advisories - Secunia |
SECUNIA |
secunia.com |
Vendor Advisory |
| SUSE Update for Multiple Packages - Advisories - Secunia |
SECUNIA |
secunia.com |
Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH |
VUPEN |
www.vupen.com |
Vendor Advisory |
| Security Announcement |
SUSE |
www.novell.com |
|
| rhn.redhat.com | Red Hat Support |
REDHAT |
www.redhat.com |
Vendor Advisory |
| Repository / Oval Repository |
OVAL |
oval.cisecurity.org |
|
| Support |
REDHAT |
www.redhat.com |
Vendor Advisory |
| Red Hat update for mysql - Advisories - Secunia |
SECUNIA |
secunia.com |
Vendor Advisory |
| MySQL Bugs: #18630: Arguments of suid routine calculated in wrong security context |
CONFIRM |
bugs.mysql.com |
Exploit |
| MySQL AB :: MySQL 5.0 Reference Manual :: G.1.3 Changes in release 5.0.25 (15 September 2006) |
CONFIRM |
dev.mysql.com |
|
| SecurityTracker.com Archives - MySQL Error in Checking suid Routine Arguments May Let Users Gain Elevated Privileges |
SECTRACK |
securitytracker.com |
|
| Ubuntu update for mysql-dfsg-5.0 - Advisories - Secunia |
SECUNIA |
secunia.com |
Vendor Advisory |
| usn/usn-338-1 - Ubuntu: Linux for human beings |
UBUNTU |
www.ubuntu.com |
|
| MySQL Lists: commits: bk commit into 5.0 tree (kroki:1.2168) BUG#18630 |
MLIST |
lists.mysql.com |
|
| MySQL Privilege Elevation and Security Bypass Vulnerabilities |
BID |
www.securityfocus.com |
Exploit |
| IBM X-Force Exchange |
XF |
exchange.xforce.ibmcloud.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|
| Red Hat | 2008-07-25 | Mark J Cox | This issue did not affect the versions of MySQL as shipped with Red Hat Enterprise Linux 2.1, 3, or 4. Issue was addressed in MySQL packages as shipped in Red Hat Enterprise Linux 5 via: https://rhn.redhat.com/errata/RHSA-2008-0364.html |
There are currently no legacy QID mappings associated with this CVE.