Security Invoker Stored Procedure privilege elevation Vulnerability

Source: Internet
Author: User
Tags mysql

MySQL AB security Invoker Stored procedure privilege elevation vulnerability.

Affected Systems:

MySQL AB mysql 5.1.x < 5.1.18.

MySQL AB mysql 5.0.x < 5.0.40.

Unaffected system:

MySQL AB MySQL 5.1.18.

MySQL AB MySQL 5.0.40.

Describe:

MySQL is a very extensive open source relational database system with a running version of various platforms.

MySQL has a vulnerability when it handles the return status of SQL security Invoker stored procedures that can be exploited by a local attacker to elevate permissions in the database system.

The mysql_change_db function in MySQL is not restored when returning from the SQL security Invoker stored procedure THD::d b_access permissions, which may allow a remote authenticated user to gain elevation of privilege. This vulnerability occurs only if a routine is defined with SQL Security Invoker, and the security environment can be correctly switched between Definer and invoker if defined with SQL security definer.

Vendor Patch:

MySQL AB

At present, the manufacturer has released the upgrade patch to fix this security issue, please go to the manufacturer's homepage to download:

Http://dev.mysql.com/get/Downloads/MySQL-5.0/mysql-5.0.41.tar.gz/from/pick

Http://dev.mysql.com/get/Downloads/MySQL-5.1/mysql-5.1.18-beta.tar.gz/from/pick



Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.