MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to execute arbitrary code by using CREATE FUNCTION to access libc calls, as demonstrated by using strcat, on_exit, and exit.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Mysql | — | Apply OS X security update 2005-007 | Dec 16, 2011 | May 2, 2005 |
| Freebsd | — | Upgrade mysql-server | Dec 10, 2025 | Mar 14, 2005 |
| Gentoo Linux | — | Upgrade dev-db/mysql. | Oct 30, 2017 | May 2, 2005 |
| Suse | — | Upgrade mysqlUpgrade mysql-Max | Feb 17, 2015 | May 2, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub