Description of problem: Functions declared as SECURITY INVOKER do not drop privileges upon return and thus make it possible for an authenticated user calling then can gain certain privileges. Version-Release number of selected component (if applicable): MySQL 5.0.x before 5.0.40 and 5.1.x before 5.1.18
This issue was addressed in: Red Hat Application Stack: http://rhn.redhat.com/errata/RHSA-2007-0894.html Red Hat Enterprise Linux: http://rhn.redhat.com/errata/RHSA-2008-0364.html
Reporter changed to security-response-team by request of Jay Turner.