CVE-2006-4031
published 2006-08-09CVE-2006-4031: MySQL 4.1 before 4.1.21 and 5.0 before 5.0.24 allows a local user to access a table through a previously created MERGE table, even after the user's privileges…
PriorityP412low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
1.74%
75.1th percentile
MySQL 4.1 before 4.1.21 and 5.0 before 5.0.24 allows a local user to access a table through a previously created MERGE table, even after the user's privileges are revoked for the original table, which might violate intended security policy.
Affected
146 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat2.1LOW
vendor_ubuntu2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qqjv-c795-8pr6: MySQL 4
ghsa_unreviewed·2022-05-01
CVE-2006-4031 [LOW] GHSA-qqjv-c795-8pr6: MySQL 4
MySQL 4.1 before 4.1.21 and 5.0 before 5.0.24 allows a local user to access a table through a previously created MERGE table, even after the user's privileges are revoked for the original table, which might violate intended security policy.
Ubuntu
MySQL vulnerabilities
vendor_ubuntu·2006-09-05·CVSS 2.1
CVE-2006-4031 [LOW] MySQL vulnerabilities
Title: MySQL vulnerabilities
Summary: MySQL vulnerabilities
Dmitri Lenev discovered that arguments of setuid SQL functions were
evaluated in the security context of the functions' definer instead of
its caller. An authenticated user with the privilege to call such a
function could exploit this to execute arbitrary statements with the
privileges of the definer of that function. (CVE-2006-4227)
Peter Gulutzan reported a potentially confusing situation of the MERGE
table engine. If an user creates a merge table, and the administrator
later revokes privileges on the original table only (without changing
the privileges on the merge table), that user still has access to the
data by using the merge table. This is intended behaviour, but might
be undesirable in some installations; this update i
Red Hat
MySQL improper permission revocation
vendor_redhat·2005-11-23·CVSS 2.1
CVE-2006-4031 [LOW] MySQL improper permission revocation
MySQL improper permission revocation
MySQL 4.1 before 4.1.21 and 5.0 before 5.0.24 allows a local user to access a table through a previously created MERGE table, even after the user's privileges are revoked for the original table, which might violate intended security policy.
Statement: This issue did not affect mysql packages as shipped with Red Hat Enterprise Linux 2.1 or 3
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-4031 MySQL improper permission revocation
bugzilla·2006-08-15·CVSS 2.1
CVE-2006-4031 [LOW] CVE-2006-4031 MySQL improper permission revocation
CVE-2006-4031 MySQL improper permission revocation
For FC6 tracking
+++ This bug was initially created as a clone of Bug #202247 +++
MySQL improper permission revocation
If a user has been granted permissions to create a MERGE table, even
after permissions have been revoked from the parent table, the user
can access the data via the MERGE table.
More information including a patch can be found here:
http://bugs.mysql.com/bug.php?id=15195
Discussion:
still needed
---
CVE-2006-4031 VULNERABLE (mysql, fixed 5.0.24) bz#202675
marking as FC6Blocker
Bugzilla
CVE-2006-4031 MySQL improper permission revocation
bugzilla·2006-08-11·CVSS 2.1
CVE-2006-4031 [LOW] CVE-2006-4031 MySQL improper permission revocation
CVE-2006-4031 MySQL improper permission revocation
MySQL improper permission revocation
If a user has been granted permissions to create a MERGE table, even
after permissions have been revoked from the parent table, the user
can access the data via the MERGE table.
More information including a patch can be found here:
http://bugs.mysql.com/bug.php?id=15195
Discussion:
moving to security response parent bug
---
This issue was addressed in:
Red Hat Application Stack:
http://rhn.redhat.com/errata/RHSA-2007-0083.html
Red Hat Enterprise Linux:
http://rhn.redhat.com/errata/RHSA-2008-0364.html
http://rhn.redhat.com/errata/RHSA-2008-0768.html
Bugzilla
CVE-2006-4031 MySQL improper permission revocation
bugzilla·2006-08-11·CVSS 2.1
CVE-2006-4031 [LOW] CVE-2006-4031 MySQL improper permission revocation
CVE-2006-4031 MySQL improper permission revocation
MySQL improper permission revocation
If a user has been granted permissions to create a MERGE table, even
after permissions have been revoked from the parent table, the user
can access the data via the MERGE table.
More information including a patch can be found here:
http://bugs.mysql.com/bug.php?id=15195
http://bugs.mysql.com/bug.php?id=15195http://dev.mysql.com/doc/refman/4.1/en/news-4-1-21.htmlhttp://dev.mysql.com/doc/refman/5.0/en/news-5-0-24.htmlhttp://docs.info.apple.com/article.html?artnum=305214http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.htmlhttp://secunia.com/advisories/21259http://secunia.com/advisories/21382http://secunia.com/advisories/21627http://secunia.com/advisories/21685http://secunia.com/advisories/21770http://secunia.com/advisories/22080http://secunia.com/advisories/24479http://secunia.com/advisories/30351http://secunia.com/advisories/31226http://securitytracker.com/id?1016617http://www.mandriva.com/security/advisories?name=MDKSA-2006:149http://www.novell.com/linux/security/advisories/2006_23_sr.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0083.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0364.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0768.htmlhttp://www.securityfocus.com/bid/19279http://www.ubuntu.com/usn/usn-338-1http://www.us-cert.gov/cas/techalerts/TA07-072A.htmlhttp://www.vupen.com/english/advisories/2006/3079http://www.vupen.com/english/advisories/2007/0930https://issues.rpath.com/browse/RPL-568https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10468http://bugs.mysql.com/bug.php?id=15195http://dev.mysql.com/doc/refman/4.1/en/news-4-1-21.htmlhttp://dev.mysql.com/doc/refman/5.0/en/news-5-0-24.htmlhttp://docs.info.apple.com/article.html?artnum=305214http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.htmlhttp://secunia.com/advisories/21259http://secunia.com/advisories/21382http://secunia.com/advisories/21627http://secunia.com/advisories/21685http://secunia.com/advisories/21770http://secunia.com/advisories/22080http://secunia.com/advisories/24479http://secunia.com/advisories/30351http://secunia.com/advisories/31226http://securitytracker.com/id?1016617http://www.mandriva.com/security/advisories?name=MDKSA-2006:149http://www.novell.com/linux/security/advisories/2006_23_sr.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0083.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0364.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0768.htmlhttp://www.securityfocus.com/bid/19279http://www.ubuntu.com/usn/usn-338-1http://www.us-cert.gov/cas/techalerts/TA07-072A.htmlhttp://www.vupen.com/english/advisories/2006/3079http://www.vupen.com/english/advisories/2007/0930https://issues.rpath.com/browse/RPL-568https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10468
2006-08-09
Published