Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2006-4227 | First vendor Publication | 2006-08-18 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:S/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 6.5 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Low |
Cvss Expoit Score | 8 | Authentication | Requires single instance |
Calculate full CVSS 2.0 Vectors scores |
Detail
MySQL before 5.0.25 and 5.1 before 5.1.12 evaluates arguments of suid routines in the security context of the routine's definer instead of the routine's caller, which allows remote authenticated users to gain privileges through a routine that has been made available using GRANT EXECUTE. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4227 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-20 | Improper Input Validation |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:10105 | |||
Oval ID: | oval:org.mitre.oval:def:10105 | ||
Title: | MySQL before 5.0.25 and 5.1 before 5.1.12 evaluates arguments of suid routines in the security context of the routine's definer instead of the routine's caller, which allows remote authenticated users to gain privileges through a routine that has been made available using GRANT EXECUTE. | ||
Description: | MySQL before 5.0.25 and 5.1 before 5.1.12 evaluates arguments of suid routines in the security context of the routine's definer instead of the routine's caller, which allows remote authenticated users to gain privileges through a routine that has been made available using GRANT EXECUTE. | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2006-4227 | Version: | 5 |
Platform(s): | Red Hat Enterprise Linux 5 CentOS Linux 5 Oracle Linux 5 | Product(s): | |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2009-03-06 | Name : RedHat Update for mysql RHSA-2008:0364-01 File : nvt/gb_RHSA-2008_0364-01_mysql.nasl |
2008-09-04 | Name : FreeBSD Ports: mysql-server File : nvt/freebsd_mysql-server12.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
28013 | MySQL SUID Routine Miscalculation Arbitrary DML Statement Execution |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2012-08-01 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20080521_mysql_on_SL5_x.nasl - Type : ACT_GATHER_INFO |
2012-01-16 | Name : The remote database server may allow a remote user access to objects for whic... File : mysql_5_1_12_suid.nasl - Type : ACT_GATHER_INFO |
2008-05-22 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2008-0364.nasl - Type : ACT_GATHER_INFO |
2007-12-13 | Name : The remote SuSE 10 host is missing a security-related patch. File : suse_mysql-2073.nasl - Type : ACT_GATHER_INFO |
2007-11-10 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-338-1.nasl - Type : ACT_GATHER_INFO |
2007-10-17 | Name : The remote openSUSE host is missing a security update. File : suse_mysql-2075.nasl - Type : ACT_GATHER_INFO |
2006-10-30 | Name : The remote FreeBSD host is missing one or more security-related updates. File : freebsd_pkg_a9c51caf660311dbab90000e35fd8194.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:19:44 |
|
2024-11-28 12:09:47 |
|
2024-08-02 12:05:06 |
|
2024-08-02 01:02:00 |
|
2024-02-02 01:04:46 |
|
2024-02-01 12:02:00 |
|
2023-09-05 12:04:28 |
|
2023-09-05 01:01:52 |
|
2023-09-02 12:04:31 |
|
2023-09-02 01:01:52 |
|
2023-08-12 12:05:21 |
|
2023-08-12 01:01:52 |
|
2023-08-11 12:04:36 |
|
2023-08-11 01:01:55 |
|
2023-08-06 12:04:21 |
|
2023-08-06 01:01:53 |
|
2023-08-04 12:04:26 |
|
2023-08-04 01:01:55 |
|
2023-07-14 12:04:25 |
|
2023-07-14 01:01:54 |
|
2023-03-29 01:04:46 |
|
2023-03-28 12:01:58 |
|
2022-10-11 12:03:55 |
|
2022-10-11 01:01:45 |
|
2021-05-04 12:04:27 |
|
2021-04-22 01:05:06 |
|
2020-05-23 00:18:15 |
|
2017-10-11 09:23:44 |
|
2017-07-20 09:23:49 |
|
2016-04-26 14:58:33 |
|
2014-02-17 10:36:55 |
|
2013-05-11 11:06:21 |
|