{"api_version":"1","generated_at":"2026-07-23T09:28:01+00:00","cve":"CVE-2003-1331","urls":{"html":"https://cve.report/CVE-2003-1331","api":"https://cve.report/api/cve/CVE-2003-1331.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2003-1331","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2003-1331"},"summary":{"title":"CVE-2003-1331","description":"Stack-based buffer overflow in the mysql_real_connect function in the MySql client library (libmysqlclient) 4.0.13 and earlier allows local users to execute arbitrary code via a long socket name, a different vulnerability than CVE-2001-1453.","state":"PUBLISHED","assigner":"mitre","published_at":"2003-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4","severity":"","vector":"AV:N/AC:H/Au:N/C:N/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:N/I:P/A:P","baseScore":4,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://archives.neohapsis.com/archives/fulldisclosure/2003-q2/1303.html","name":"http://archives.neohapsis.com/archives/fulldisclosure/2003-q2/1303.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"NEOHAPSIS - Peace of Mind Through Integrity and Insight","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://bugs.mysql.com/bug.php?id=564","name":"http://bugs.mysql.com/bug.php?id=564","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"MySQL Bugs: #564: mysql_real_connect buffer overflow in unix socket name.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/7887","name":"http://www.securityfocus.com/bid/7887","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"MySQL libmysqlclient Library mysql_real_connect() Buffer Overrun Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/12337","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/12337","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2003-1331","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2003-1331","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2003","cve_id":"1331","vulnerable":"1","versionEndIncluding":"4.0.9","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"mysql","cpe6":"*","cpe7":"gamma","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[{"cvename":"CVE-2003-1331","organization":"Red Hat","lastmodified":"2007-06-29","contributor":"Joshua Bressers","statementText":"Red Hat does not consider this issue to be a security vulnerability since no trust boundary is crossed. The user must voluntarily interact with the attack mechanism to exploit this flaw, with the result being the ability to run code as themselves.","cve_year":"2003","cve_id":"1331","crc32":"9bc7012c"}],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T02:28:01.566Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"mysql-mysqlrealconnect-bo(12337)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/12337"},{"name":"7887","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/7887"},{"name":"20030612 libmysqlclient 4.x and below mysql_real_connect() buffer overflow.","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://archives.neohapsis.com/archives/fulldisclosure/2003-q2/1303.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://bugs.mysql.com/bug.php?id=564"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2003-06-12T00:00:00.000Z","descriptions":[{"lang":"en","value":"Stack-based buffer overflow in the mysql_real_connect function in the MySql client library (libmysqlclient) 4.0.13 and earlier allows local users to execute arbitrary code via a long socket name, a different vulnerability than CVE-2001-1453."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"mysql-mysqlrealconnect-bo(12337)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/12337"},{"name":"7887","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/7887"},{"name":"20030612 libmysqlclient 4.x and below mysql_real_connect() buffer overflow.","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://archives.neohapsis.com/archives/fulldisclosure/2003-q2/1303.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://bugs.mysql.com/bug.php?id=564"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2003-1331","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Stack-based buffer overflow in the mysql_real_connect function in the MySql client library (libmysqlclient) 4.0.13 and earlier allows local users to execute arbitrary code via a long socket name, a different vulnerability than CVE-2001-1453."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"mysql-mysqlrealconnect-bo(12337)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/12337"},{"name":"7887","refsource":"BID","url":"http://www.securityfocus.com/bid/7887"},{"name":"20030612 libmysqlclient 4.x and below mysql_real_connect() buffer overflow.","refsource":"FULLDISC","url":"http://archives.neohapsis.com/archives/fulldisclosure/2003-q2/1303.html"},{"name":"http://bugs.mysql.com/bug.php?id=564","refsource":"CONFIRM","url":"http://bugs.mysql.com/bug.php?id=564"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2003-1331","datePublished":"2007-06-25T23:00:00.000Z","dateReserved":"2007-06-25T00:00:00.000Z","dateUpdated":"2024-08-08T02:28:01.566Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2003-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:N/I:P/A:P","baseScore":4,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":4.9,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:mysql:*:gamma:*:*:*:*:*:*","versionEndIncluding":"4.0.9","matchCriteriaId":"B90917FD-7681-4551-9FB1-214348C6A2D6"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2003","CveId":"1331","Ordinal":"1","Title":"CVE-2003-1331","CVE":"CVE-2003-1331","Year":"2003"},"notes":[{"CveYear":"2003","CveId":"1331","Ordinal":"1","NoteData":"Stack-based buffer overflow in the mysql_real_connect function in the MySql client library (libmysqlclient) 4.0.13 and earlier allows local users to execute arbitrary code via a long socket name, a different vulnerability than CVE-2001-1453.","Type":"Description","Title":"CVE-2003-1331"},{"CveYear":"2003","CveId":"1331","Ordinal":"2","NoteData":"2007-06-25","Type":"Other","Title":"Published"},{"CveYear":"2003","CveId":"1331","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}