MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to bypass library path restrictions and execute arbitrary libraries by using INSERT INTO to modify the mysql.func table, which is processed by the udf_init function.
CVSS Details
- CVSS 3.1 Base Score: 8.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Mysql | — | Apply OS X security update 2005-007 | Dec 16, 2011 | May 2, 2005 |
| Freebsd | — | Upgrade mysql-server | Dec 10, 2025 | Mar 14, 2005 |
| Gentoo Linux | — | Upgrade dev-db/mysql. | Oct 30, 2017 | May 2, 2005 |
| Suse | — | Upgrade mysql-MaxUpgrade mysql | Feb 17, 2015 | May 2, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub