Red Hat Bugzilla – Bug 202246
CVE-2006-4031 MySQL improper permission revocation
Last modified: 2013-07-02 23:10:41 EDT
MySQL improper permission revocation If a user has been granted permissions to create a MERGE table, even after permissions have been revoked from the parent table, the user can access the data via the MERGE table. More information including a patch can be found here: http://bugs.mysql.com/bug.php?id=15195
moving to security response parent bug
This issue was addressed in: Red Hat Application Stack: http://rhn.redhat.com/errata/RHSA-2007-0083.html Red Hat Enterprise Linux: http://rhn.redhat.com/errata/RHSA-2008-0364.html http://rhn.redhat.com/errata/RHSA-2008-0768.html