CVE-2007-1420
Summary
| CVE | CVE-2007-1420 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-03-12 23:19:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | MySQL 5.x before 5.0.36 allows local users to cause a denial of service (database crash) by performing information_schema table subselects and using ORDER BY to sort a single-row result, which prevents certain structure elements from being initialized and triggers a NULL dereference in the filesort function. |
Risk And Classification
Primary CVSS: v2.0 2.1 from [email protected]
AV:L/AC:L/Au:N/C:N/I:N/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:L/AC:L/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mysql | Mysql | 5.0.0 | All | All | All |
| Application | Mysql | Mysql | 5.0.1 | All | All | All |
| Application | Mysql | Mysql | 5.0.10 | All | All | All |
| Application | Mysql | Mysql | 5.0.15 | All | All | All |
| Application | Mysql | Mysql | 5.0.16 | All | All | All |
| Application | Mysql | Mysql | 5.0.17 | All | All | All |
| Application | Mysql | Mysql | 5.0.2 | All | All | All |
| Application | Mysql | Mysql | 5.0.20 | All | All | All |
| Application | Mysql | Mysql | 5.0.24 | All | All | All |
| Application | Mysql | Mysql | 5.0.3 | All | All | All |
| Application | Mysql | Mysql | 5.0.30 | All | All | All |
| Application | Mysql | Mysql | 5.0.4 | All | All | All |
| Application | Mysql | Mysql | 5.0.5 | All | All | All |
| Application | Mysql | Mysql | All | All | All | All |
| Application | Oracle | Mysql | 5.0.32 | All | All | All |
| Application | Oracle | Mysql | 5.0.41 | All | All | All |
| Application | Oracle | Mysql | 5.0.6 | All | All | All |
| Application | Oracle | Mysql | 5.0.7 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| MySQL Bugs: #24630: Subselect query crashes mysqld | af854a3a-2127-422b-91ae-364da2661108 | bugs.mysql.com | |
| Support / Security / Advisories / / MDKSA-2007:139 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| MySQL Single-Row Subselect Denial of Service - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| MySQL Single Row SubSelect Remote Denial Of Service Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit, Patch |
| Ubuntu update for mysql - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Vendor Advisory |
| rPath update for mysql - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| MySQL 5 Single Row Subselect Denial of Service - SecurityReason.com | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| Mandriva update for mysql - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| 404 - Page not found! - SEC Consult | af854a3a-2127-422b-91ae-364da2661108 | www.sec-consult.com | Exploit |
| MySQL AB :: MySQL 5.0 Reference Manual :: C.1.13 Release Notes for MySQL Enterprise 5.0.36 [MRU] (20 February 2007) | af854a3a-2127-422b-91ae-364da2661108 | dev.mysql.com | Vendor Advisory |
| issues.rpath.com/browse/RPL-1127 | af854a3a-2127-422b-91ae-364da2661108 | issues.rpath.com | |
| Gentoo update for mysql - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| USN-440-1: MySQL vulnerability | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Red Hat update for mysql - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| MySQL Single Row Subselect Statements Let Remote Users Deny Service - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Gentoo Linux Documentation -- MySQL: Two Denial of Service vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2008-07-25 | Joshua Bressers | This issue did not affect mysql packages as shipped in Red Hat Enterprise Linux 2.1, 3, and 4. Issue was addressed in mysql packages as shipped in Red Hat Enterprise Linux 5 via: https://rhn.redhat.com/errata/RHSA-2008-0364.html |
There are currently no legacy QID mappings associated with this CVE.