PT-2006-4875 · Oracle+1 · Mysql Server+1
Christian Hammers
+1
·
Published
2006-08-09
·
Updated
2019-12-17
·
CVE-2006-4031
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
MySQL versions 4.1 through 4.1.20
MySQL versions 5.0 through 5.0.23
Description
A local user can access a table through a previously created MERGE table, even after the user's privileges are revoked for the original table, potentially violating intended security policy.
Recommendations
For MySQL versions 4.1 through 4.1.20, update to version 4.1.21 or later.
For MySQL versions 5.0 through 5.0.23, update to version 5.0.24 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mysql Server
Red Hat