MySQL improperly evaluates the argument passed to suid in the context of the routine's definer, not in the context of the caller. This could possibly lead to privilege escalation. The upstream bug has more information: http://bugs.mysql.com/bug.php?id=18630