Unrated severityNVD Advisory· Published Aug 18, 2006· Updated Apr 16, 2026
CVE-2006-4227
CVE-2006-4227
Description
MySQL before 5.0.25 and 5.1 before 5.1.12 evaluates arguments of suid routines in the security context of the routine's definer instead of the routine's caller, which allows remote authenticated users to gain privileges through a routine that has been made available using GRANT EXECUTE.
Affected products
12cpe:2.3:a:mysql:mysql:5.0.1:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:mysql:mysql:5.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:mysql:mysql:5.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:mysql:mysql:5.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:mysql:mysql:5.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:mysql:mysql:5.0.20:*:*:*:*:*:*:*
- cpe:2.3:a:mysql:mysql:5.0.22.1.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:mysql:mysql:5.0.24:*:*:*:*:*:*:*
- cpe:2.3:a:mysql:mysql:5.1.5:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.0.0:alpha:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:oracle:mysql:5.0.0:alpha:*:*:*:*:*:*
- cpe:2.3:a:oracle:mysql:5.1.6:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:mysql:5.1.9:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:mysql:5.1.10:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
16- bugs.mysql.com/bug.phpnvdExploit
- www.securityfocus.com/bid/19559nvdExploit
- secunia.com/advisories/21506nvdVendor Advisory
- secunia.com/advisories/21770nvdVendor Advisory
- secunia.com/advisories/22080nvdVendor Advisory
- secunia.com/advisories/30351nvdVendor Advisory
- www.redhat.com/support/errata/RHSA-2007-0083.htmlnvdVendor Advisory
- www.redhat.com/support/errata/RHSA-2008-0364.htmlnvdVendor Advisory
- www.vupen.com/english/advisories/2006/3306nvdVendor Advisory
- dev.mysql.com/doc/refman/5.0/en/news-5-0-25.htmlnvd
- lists.mysql.com/commits/7918nvd
- securitytracker.com/idnvd
- www.novell.com/linux/security/advisories/2006_23_sr.htmlnvd
- www.ubuntu.com/usn/usn-338-1nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/28442nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10105nvd
News mentions
0No linked articles in our index yet.