CVE-2006-4227

Impact:
Moderate
Public Date:
2006-03-29
Bugzilla:
216427: CVE-2006-4227 mysql improper suid argument evaluation

The MITRE CVE dictionary describes this issue as:

MySQL before 5.0.25 and 5.1 before 5.1.12 evaluates arguments of suid routines in the security context of the routine's definer instead of the routine's caller, which allows remote authenticated users to gain privileges through a routine that has been made available using GRANT EXECUTE.

Find out more about CVE-2006-4227 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

This issue did not affect the versions of MySQL as shipped with Red Hat Enterprise Linux 2.1, 3, or 4.

Issue was addressed in MySQL packages as shipped in Red Hat Enterprise Linux 5 via:

https://rhn.redhat.com/errata/RHSA-2008-0364.html

Red Hat Security Errata

Platform Errata Release Date
Red Hat Application Stack v1 for Enterprise Linux AS (v.4) (mysql) RHSA-2007:0083 2007-02-19
Red Hat Enterprise Linux 5 (mysql) RHSA-2008:0364 2008-05-20

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.