CVE-2007-6304
Summary
| CVE | CVE-2007-6304 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-12-10 21:46:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The federated engine in MySQL 5.0.x before 5.0.51a, 5.1.x before 5.1.23, and 6.0.x before 6.0.4, when performing a certain SHOW TABLE STATUS query, allows remote MySQL servers to cause a denial of service (federated handler crash and daemon crash) via a response that lacks the minimum required number of columns. |
Risk And Classification
Primary CVSS: v2.0 5 from [email protected]
AV:N/AC:L/Au:N/C:N/I:N/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:L/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mysql | Mysql | 5.0.0 | All | All | All |
| Application | Mysql | Mysql | 5.0.1 | All | All | All |
| Application | Mysql | Mysql | 5.0.10 | All | All | All |
| Application | Mysql | Mysql | 5.0.15 | All | All | All |
| Application | Mysql | Mysql | 5.0.16 | All | All | All |
| Application | Mysql | Mysql | 5.0.17 | All | All | All |
| Application | Mysql | Mysql | 5.0.2 | All | All | All |
| Application | Mysql | Mysql | 5.0.20 | All | All | All |
| Application | Mysql | Mysql | 5.0.22.1.0.1 | All | All | All |
| Application | Mysql | Mysql | 5.0.24 | All | All | All |
| Application | Mysql | Mysql | 5.0.3 | All | All | All |
| Application | Mysql | Mysql | 5.0.4 | All | All | All |
| Application | Mysql | Mysql | 5.0.5 | All | All | All |
| Application | Mysql | Mysql | 5.0.5.0.21 | All | All | All |
| Application | Oracle | Mysql | 5.0.0 | alpha | All | All |
| Application | Oracle | Mysql | 5.0.11 | All | All | All |
| Application | Oracle | Mysql | 5.0.12 | All | All | All |
| Application | Oracle | Mysql | 5.0.13 | All | All | All |
| Application | Oracle | Mysql | 5.0.14 | All | All | All |
| Application | Oracle | Mysql | 5.0.18 | All | All | All |
| Application | Oracle | Mysql | 5.0.19 | All | All | All |
| Application | Oracle | Mysql | 5.0.21 | All | All | All |
| Application | Oracle | Mysql | 5.0.22 | All | All | All |
| Application | Oracle | Mysql | 5.0.27 | All | All | All |
| Application | Oracle | Mysql | 5.0.3 | beta | All | All |
| Application | Oracle | Mysql | 5.0.33 | All | All | All |
| Application | Oracle | Mysql | 5.0.37 | All | All | All |
| Application | Oracle | Mysql | 5.0.41 | All | All | All |
| Application | Oracle | Mysql | 5.0.6 | All | All | All |
| Application | Oracle | Mysql | 5.0.7 | All | All | All |
| Application | Oracle | Mysql | 5.0.8 | All | All | All |
| Application | Oracle | Mysql | 5.0.9 | All | All | All |
| Application | Oracle | Mysql | 5.1.1 | All | All | All |
| Application | Oracle | Mysql | 5.1.10 | All | All | All |
| Application | Oracle | Mysql | 5.1.11 | All | All | All |
| Application | Oracle | Mysql | 5.1.12 | All | All | All |
| Application | Oracle | Mysql | 5.1.13 | All | All | All |
| Application | Oracle | Mysql | 5.1.14 | All | All | All |
| Application | Oracle | Mysql | 5.1.15 | All | All | All |
| Application | Oracle | Mysql | 5.1.16 | All | All | All |
| Application | Oracle | Mysql | 5.1.17 | All | All | All |
| Application | Oracle | Mysql | 5.1.2 | All | All | All |
| Application | Oracle | Mysql | 6.0.0 | All | All | All |
| Application | Oracle | Mysql | 6.0.1 | All | All | All |
| Application | Oracle | Mysql | 6.0.2 | All | All | All |
| Application | Oracle | Mysql | 6.0.3 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| USN-559-1: MySQL vulnerabilities | Ubuntu security notices | af854a3a-2127-422b-91ae-364da2661108 | usn.ubuntu.com | |
| issues.rpath.com/browse/RPL-2187 | af854a3a-2127-422b-91ae-364da2661108 | issues.rpath.com | |
| MySQL Security Issue and Two Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| MySQL Bugs: #29801: Federated engine crashes local server if remote server sends malicious response | af854a3a-2127-422b-91ae-364da2661108 | bugs.mysql.com | Exploit |
| MySQL AB :: MySQL 6.0 Reference Manual :: C.1.2 Changes in MySQL 6.0.4 (Not yet released) | af854a3a-2127-422b-91ae-364da2661108 | dev.mysql.com | |
| MySQL AB :: MySQL 5.0 Reference Manual :: C.1.3 Release Notes for MySQL Enterprise 5.0.52 [MRU] (30 Nov 2007) | af854a3a-2127-422b-91ae-364da2661108 | dev.mysql.com | |
| Advisories | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| [security-announce] SUSE Security Summary Report SUSE-SR:2008:003 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| rPath update for mysql - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Mandriva update for mysql - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Advisories:rPSA-2008-0040 - rPath Wiki | af854a3a-2127-422b-91ae-364da2661108 | wiki.rpath.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SUSE Update for Multiple Packages - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Debian update for mysql-dfsg-5.0 - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| SecurityTracker.com Archives - MySQL Bugs Let Remote Authenticated Users Gain Elevated Privileges and Deny Service | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Gentoo Linux Documentation -- MySQL: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| MySQL Server Privilege Escalation And Denial Of Service Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Advisories | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| osvdb.org/42609 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Ubuntu update for mysql - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Gentoo update for mysql - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| MySQL Lists: announce: MySQL 5.0.51a has been released | af854a3a-2127-422b-91ae-364da2661108 | lists.mysql.com | |
| Debian -- Security Information -- DSA-1451-1 mysql-dfsg-5.0 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| MySQL :: MySQL 5.1 Reference Manual :: C.1.9 Changes in MySQL 5.1.23 (29 January 2008) | af854a3a-2127-422b-91ae-364da2661108 | dev.mysql.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2007-12-14 | Mark J Cox | Not vulnerable. The MySQL versions as shipped in Red Hat Enterprise Linux 2.1, 3, and 4 do not support federated storage engine. The MySQL package as shipped in Red Hat Enterprise Linux 5, Red Hat Application Stack v1, and Red Hat Application Stack v2 are not compiled with support for federated storage engine. |
There are currently no legacy QID mappings associated with this CVE.