---
title: "CVE-2006-4227\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2006-4227?format=md
keywords: index, follow
---

# CVE-2006-4227

Publication date 18 August 2006

Last updated 17 July 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

MySQL before 5.0.25 and 5.1 before 5.1.12 evaluates arguments of suid
routines in the security context of the routine's definer instead of the
routine's caller, which allows remote authenticated users to gain
privileges through a routine that has been made available using GRANT
EXECUTE.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| mysql-dfsg-5.0 | 7.04 feisty | Fixed 5.0.38-0ubuntu1 |
| 6.10 edgy | Fixed 5.0.24a-9ubuntu0.1 |
| 6.06 LTS dapper | Fixed 5.0.22-0ubuntu6.06.3 |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4227)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2006-4227)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2006-4227)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2006-4227)

### Related Ubuntu Security Notices (USN)

+ [USN-338-1](https://usn.ubuntu.com/USN-338-1)
+ MySQL vulnerabilities
+ 5 September 2006

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2006-4227>
