Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2006-4227
Description:MySQL before 5.0.25 and 5.1 before 5.1.12 evaluates arguments of suid routines in the security context of the routine's definer instead of the routine's caller, which allows remote authenticated users to gain privileges through a routine that has been made available using GRANT EXECUTE.
Test IDs: 1.3.6.1.4.1.25623.1.0.57526  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2006-4227
BugTraq ID: 19559
http://www.securityfocus.com/bid/19559
http://lists.mysql.com/commits/7918
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10105
RedHat Security Advisories: RHSA-2007:0083
http://www.redhat.com/support/errata/RHSA-2007-0083.html
RedHat Security Advisories: RHSA-2008:0364
http://www.redhat.com/support/errata/RHSA-2008-0364.html
http://securitytracker.com/id?1016709
http://secunia.com/advisories/21506
http://secunia.com/advisories/21770
http://secunia.com/advisories/22080
http://secunia.com/advisories/30351
SuSE Security Announcement: SUSE-SR:2006:023 (Google Search)
http://www.novell.com/linux/security/advisories/2006_23_sr.html
http://www.ubuntu.com/usn/usn-338-1
http://www.vupen.com/english/advisories/2006/3306
XForce ISS Database: mysql-grant-execute-privilege-escalation(28442)
https://exchange.xforce.ibmcloud.com/vulnerabilities/28442




© 1998-2025 E-Soft Inc. All rights reserved.