CVE-2005-0709

Publication date 2 May 2005

Last updated 17 July 2025


Ubuntu priority

MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to execute arbitrary code by using CREATE FUNCTION to access libc calls, as demonstrated by using strcat, on_exit, and exit.

Status

Package Ubuntu Release Status
mysql-dfsg 7.04 feisty Not in release
6.10 edgy
Fixed 4.0.24-10ubuntu2
6.06 LTS dapper
Fixed 4.0.24-10ubuntu2
mysql-dfsg-4.1 7.04 feisty Not in release
6.10 edgy
Fixed 4.1.15-1ubuntu5
6.06 LTS dapper
Fixed 4.1.15-1ubuntu5
mysql-dfsg-5.0 7.04 feisty
Fixed 5.0.38-0ubuntu1
6.10 edgy
Fixed 5.0.24a-9ubuntu0.1
6.06 LTS dapper
Fixed 5.0.22-0ubuntu6.06.3

References

Related Ubuntu Security Notices (USN)

    • USN-96-1
    • mySQL vulnerabilities
    • 16 March 2005

Other references