CVE-2006-4227
MySQL 4/5 - SUID Routine Miscalculation Arbitrary DML Statement Execution
Severity Score
6.5
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
3
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
MySQL before 5.0.25 and 5.1 before 5.1.12 evaluates arguments of suid routines in the security context of the routine's definer instead of the routine's caller, which allows remote authenticated users to gain privileges through a routine that has been made available using GRANT EXECUTE.
MySQL anterior a 5.0.25 y 5.1 anterior a 5.1.12 evalúa los argumentos de rutinas suid en el contexto de seguridad del creador de la rutina en lugar del de aquel que llama a la rutina, lo que permite a usuarios autenticados remotamente escalar privilegios a través de una rutina que ha sido puesta a su disposición utilizando GRANT EXECUTE.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2006-08-17 First Exploit
- 2006-08-18 CVE Reserved
- 2006-08-18 CVE Published
- 2024-07-08 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-20: Improper Input Validation
CAPEC
References (19)
URL | Tag | Source |
---|---|---|
http://dev.mysql.com/doc/refman/5.0/en/news-5-0-25.html | X_refsource_confirm | |
http://lists.mysql.com/commits/7918 | Mailing List | |
http://securitytracker.com/id?1016709 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/28442 | Vdb Entry | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10105 | Signature |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/28398 | 2006-08-17 | |
http://bugs.mysql.com/bug.php?id=18630 | 2024-08-07 | |
http://www.securityfocus.com/bid/19559 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/21506 | 2019-12-17 | |
http://secunia.com/advisories/21770 | 2019-12-17 | |
http://secunia.com/advisories/22080 | 2019-12-17 | |
http://secunia.com/advisories/30351 | 2019-12-17 | |
http://www.novell.com/linux/security/advisories/2006_23_sr.html | 2019-12-17 | |
http://www.redhat.com/support/errata/RHSA-2007-0083.html | 2019-12-17 | |
http://www.redhat.com/support/errata/RHSA-2008-0364.html | 2019-12-17 | |
http://www.ubuntu.com/usn/usn-338-1 | 2019-12-17 | |
http://www.vupen.com/english/advisories/2006/3306 | 2019-12-17 | |
https://access.redhat.com/security/cve/CVE-2006-4227 | 2008-05-20 | |
https://bugzilla.redhat.com/show_bug.cgi?id=216427 | 2008-05-20 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mysql Search vendor "Mysql" | Mysql Search vendor "Mysql" for product "Mysql" | 5.0.1 Search vendor "Mysql" for product "Mysql" and version "5.0.1" | - |
Affected
| ||||||
Mysql Search vendor "Mysql" | Mysql Search vendor "Mysql" for product "Mysql" | 5.0.2 Search vendor "Mysql" for product "Mysql" and version "5.0.2" | - |
Affected
| ||||||
Mysql Search vendor "Mysql" | Mysql Search vendor "Mysql" for product "Mysql" | 5.0.3 Search vendor "Mysql" for product "Mysql" and version "5.0.3" | - |
Affected
| ||||||
Mysql Search vendor "Mysql" | Mysql Search vendor "Mysql" for product "Mysql" | 5.0.4 Search vendor "Mysql" for product "Mysql" and version "5.0.4" | - |
Affected
| ||||||
Mysql Search vendor "Mysql" | Mysql Search vendor "Mysql" for product "Mysql" | 5.0.20 Search vendor "Mysql" for product "Mysql" and version "5.0.20" | - |
Affected
| ||||||
Mysql Search vendor "Mysql" | Mysql Search vendor "Mysql" for product "Mysql" | 5.0.22.1.0.1 Search vendor "Mysql" for product "Mysql" and version "5.0.22.1.0.1" | - |
Affected
| ||||||
Mysql Search vendor "Mysql" | Mysql Search vendor "Mysql" for product "Mysql" | 5.0.24 Search vendor "Mysql" for product "Mysql" and version "5.0.24" | - |
Affected
| ||||||
Mysql Search vendor "Mysql" | Mysql Search vendor "Mysql" for product "Mysql" | 5.1.5 Search vendor "Mysql" for product "Mysql" and version "5.1.5" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.0.0 Search vendor "Oracle" for product "Mysql" and version "5.0.0" | alpha |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.1.6 Search vendor "Oracle" for product "Mysql" and version "5.1.6" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.1.9 Search vendor "Oracle" for product "Mysql" and version "5.1.9" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | 5.1.10 Search vendor "Oracle" for product "Mysql" and version "5.1.10" | - |
Affected
|