CVE-2009-4019
Summary
| CVE | CVE-2009-4019 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-11-30 17:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of certain SELECT statements with subqueries, and does not (2) preserve certain null_value flags during execution of statements that use the GeomFromWKB function, which allows remote authenticated users to cause a denial of service (daemon crash) via a crafted statement. |
Risk And Classification
Primary CVSS: v2.0 4 from [email protected]
AV:N/AC:L/Au:S/C:N/I:N/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:L/Au:S/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mysql | Mysql | 5.0.0 | All | All | All |
| Application | Mysql | Mysql | 5.0.1 | All | All | All |
| Application | Mysql | Mysql | 5.0.10 | All | All | All |
| Application | Mysql | Mysql | 5.0.15 | All | All | All |
| Application | Mysql | Mysql | 5.0.16 | All | All | All |
| Application | Mysql | Mysql | 5.0.17 | All | All | All |
| Application | Mysql | Mysql | 5.0.2 | All | All | All |
| Application | Mysql | Mysql | 5.0.20 | All | All | All |
| Application | Mysql | Mysql | 5.0.22.1.0.1 | All | All | All |
| Application | Mysql | Mysql | 5.0.24 | All | All | All |
| Application | Mysql | Mysql | 5.0.3 | All | All | All |
| Application | Mysql | Mysql | 5.0.30 | All | All | All |
| Application | Mysql | Mysql | 5.0.36 | All | All | All |
| Application | Mysql | Mysql | 5.0.4 | All | All | All |
| Application | Mysql | Mysql | 5.0.44 | All | All | All |
| Application | Mysql | Mysql | 5.0.5 | All | All | All |
| Application | Mysql | Mysql | 5.0.5.0.21 | All | All | All |
| Application | Mysql | Mysql | 5.0.54 | All | All | All |
| Application | Mysql | Mysql | 5.0.56 | All | All | All |
| Application | Mysql | Mysql | 5.0.60 | All | All | All |
| Application | Mysql | Mysql | 5.0.66 | All | All | All |
| Application | Mysql | Mysql | 5.0.82 | All | All | All |
| Application | Mysql | Mysql | 5.1.23 | All | All | All |
| Application | Mysql | Mysql | 5.1.32 | All | All | All |
| Application | Mysql | Mysql | 5.1.5 | All | All | All |
| Application | Oracle | Mysql | 5.0.0 | alpha | All | All |
| Application | Oracle | Mysql | 5.0.11 | All | All | All |
| Application | Oracle | Mysql | 5.0.12 | All | All | All |
| Application | Oracle | Mysql | 5.0.13 | All | All | All |
| Application | Oracle | Mysql | 5.0.14 | All | All | All |
| Application | Oracle | Mysql | 5.0.18 | All | All | All |
| Application | Oracle | Mysql | 5.0.19 | All | All | All |
| Application | Oracle | Mysql | 5.0.21 | All | All | All |
| Application | Oracle | Mysql | 5.0.22 | All | All | All |
| Application | Oracle | Mysql | 5.0.23 | All | All | All |
| Application | Oracle | Mysql | 5.0.25 | All | All | All |
| Application | Oracle | Mysql | 5.0.26 | All | All | All |
| Application | Oracle | Mysql | 5.0.27 | All | All | All |
| Application | Oracle | Mysql | 5.0.3 | beta | All | All |
| Application | Oracle | Mysql | 5.0.30 | sp1 | All | All |
| Application | Oracle | Mysql | 5.0.32 | All | All | All |
| Application | Oracle | Mysql | 5.0.33 | All | All | All |
| Application | Oracle | Mysql | 5.0.37 | All | All | All |
| Application | Oracle | Mysql | 5.0.38 | All | All | All |
| Application | Oracle | Mysql | 5.0.41 | All | All | All |
| Application | Oracle | Mysql | 5.0.42 | All | All | All |
| Application | Oracle | Mysql | 5.0.45 | All | All | All |
| Application | Oracle | Mysql | 5.0.50 | All | All | All |
| Application | Oracle | Mysql | 5.0.51 | All | All | All |
| Application | Oracle | Mysql | 5.0.51a | All | All | All |
| Application | Oracle | Mysql | 5.0.52 | All | All | All |
| Application | Oracle | Mysql | 5.0.6 | All | All | All |
| Application | Oracle | Mysql | 5.0.7 | All | All | All |
| Application | Oracle | Mysql | 5.0.75 | All | All | All |
| Application | Oracle | Mysql | 5.0.77 | All | All | All |
| Application | Oracle | Mysql | 5.0.8 | All | All | All |
| Application | Oracle | Mysql | 5.0.81 | All | All | All |
| Application | Oracle | Mysql | 5.0.83 | All | All | All |
| Application | Oracle | Mysql | 5.1 | All | All | All |
| Application | Oracle | Mysql | 5.1.1 | All | All | All |
| Application | Oracle | Mysql | 5.1.10 | All | All | All |
| Application | Oracle | Mysql | 5.1.11 | All | All | All |
| Application | Oracle | Mysql | 5.1.12 | All | All | All |
| Application | Oracle | Mysql | 5.1.13 | All | All | All |
| Application | Oracle | Mysql | 5.1.14 | All | All | All |
| Application | Oracle | Mysql | 5.1.15 | All | All | All |
| Application | Oracle | Mysql | 5.1.16 | All | All | All |
| Application | Oracle | Mysql | 5.1.17 | All | All | All |
| Application | Oracle | Mysql | 5.1.18 | All | All | All |
| Application | Oracle | Mysql | 5.1.19 | All | All | All |
| Application | Oracle | Mysql | 5.1.2 | All | All | All |
| Application | Oracle | Mysql | 5.1.20 | All | All | All |
| Application | Oracle | Mysql | 5.1.21 | All | All | All |
| Application | Oracle | Mysql | 5.1.22 | All | All | All |
| Application | Oracle | Mysql | 5.1.3 | All | All | All |
| Application | Oracle | Mysql | 5.1.30 | All | All | All |
| Application | Oracle | Mysql | 5.1.4 | All | All | All |
| Application | Oracle | Mysql | 5.1.6 | All | All | All |
| Application | Oracle | Mysql | 5.1.7 | All | All | All |
| Application | Oracle | Mysql | 5.1.8 | All | All | All |
| Application | Oracle | Mysql | 5.1.9 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| MySQL :: MySQL 5.1 Reference Manual :: C.1.2 Changes in MySQL 5.1.41 (05 November 2009) | af854a3a-2127-422b-91ae-364da2661108 | dev.mysql.com | |
| USN-897-1: MySQL vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | ubuntu.com | |
| 'Re: [oss-security] CVE Request - MySQL - 5.0.88' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| [SECURITY] Fedora 10 Update: mysql-5.0.88-1.fc10 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| '[oss-security] CVE Request - MySQL - 5.0.88' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Bug 540906 – CVE-2009-4019 mysql: DoS (crash) when comparing GIS items from subquery and when handling subqueires in WHERE and assigning a SELECT result to a @variable | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| MySQL Bugs: #48291: crash with row() operator,select into @var, and subquery returning multiple rows | af854a3a-2127-422b-91ae-364da2661108 | bugs.mysql.com | |
| MySQL :: MySQL 5.0 Reference Manual :: C.1.2 Changes in MySQL 5.0.88 (04 November 2009) | af854a3a-2127-422b-91ae-364da2661108 | dev.mysql.com | |
| APPLE-SA-2010-03-29-1 Security Update 2010-002 / Mac OS X v10.6.3 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| marc.info | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| About the security content of Security Update 2010-002 / Mac OS X v10.6.3 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| Ubuntu update for mysql-dfsg-5 and mysql-dfsg-5.1 - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| USN-1397-1: MySQL vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Fedora update for mysql - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2010:011 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Debian update for mysql-dfsg-5.0 - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| MySQL Bugs: #47780: crash when comparing GIS items from subquery | af854a3a-2127-422b-91ae-364da2661108 | bugs.mysql.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Debian -- Security Information -- DSA-1997-1 mysql-dfsg-5.0 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.