MySQL 5.x Unspecified Buffer Overflow Vulnerability
BID:36242
Info
MySQL 5.x Unspecified Buffer Overflow Vulnerability
| Bugtraq ID: | 36242 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 03 2009 12:00AM |
| Updated: | Sep 03 2009 10:02PM |
| Credit: | Intervydis |
| Vulnerable: |
MySQL AB MySQL 5.1.32 MySQL AB MySQL 5.1.31 MySQL AB MySQL 5.1.30 MySQL AB MySQL 5.1.26 MySQL AB MySQL 5.1.23 MySQL AB MySQL 5.1.22 MySQL AB MySQL 5.1.18 MySQL AB MySQL 5.1.17 MySQL AB MySQL 5.1.16 MySQL AB MySQL 5.1.15 MySQL AB MySQL 5.1.14 MySQL AB MySQL 5.1.13 MySQL AB MySQL 5.1.12 MySQL AB MySQL 5.1.11 MySQL AB MySQL 5.1.10 MySQL AB MySQL 5.1.9 MySQL AB MySQL 5.1.6 MySQL AB MySQL 5.1.5 MySQL AB MySQL 5.0.75 MySQL AB MySQL 5.0.66 MySQL AB MySQL 5.0.60 MySQL AB MySQL 5.0.52 MySQL AB MySQL 5.0.51 MySQL AB MySQL 5.0.50 MySQL AB MySQL 5.0.49 MySQL AB MySQL 5.0.48 MySQL AB MySQL 5.0.47 MySQL AB MySQL 5.0.46 MySQL AB MySQL 5.0.45 MySQL AB MySQL 5.0.44 MySQL AB MySQL 5.0.42 MySQL AB MySQL 5.0.40 MySQL AB MySQL 5.0.39 MySQL AB MySQL 5.0.38 MySQL AB MySQL 5.0.37 MySQL AB MySQL 5.0.36 MySQL AB MySQL 5.0.33 MySQL AB MySQL 5.0.32 MySQL AB MySQL 5.0.27 MySQL AB MySQL 5.0.26 MySQL AB MySQL 5.0.24 MySQL AB MySQL 5.0.22 -1-0.1 MySQL AB MySQL 5.0.22 MySQL AB MySQL 5.0.21 MySQL AB MySQL 5.0.20 MySQL AB MySQL 5.0.19 MySQL AB MySQL 5.0.18 MySQL AB MySQL 5.0.4 MySQL AB MySQL 5.0.3 MySQL AB MySQL 5.0.2 MySQL AB MySQL 5.0.1 MySQL AB MySQL 5.0 .0-alpha MySQL AB MySQL 5.0 .0-0 MySQL AB MySQL 5.0 |
| Not Vulnerable: | |
Discussion
MySQL 5.x Unspecified Buffer Overflow Vulnerability
MySQL is prone to a buffer-overflow vulnerability because if fails to perform adequate boundary checks on user-supplied data.
An attacker can leverage this issue to execute arbitrary code within the context of the vulnerable application. Failed exploit attempts will result in a denial-of-service condition.
This issue affects MySQL 5.x; other versions may also be vulnerable.
MySQL is prone to a buffer-overflow vulnerability because if fails to perform adequate boundary checks on user-supplied data.
An attacker can leverage this issue to execute arbitrary code within the context of the vulnerable application. Failed exploit attempts will result in a denial-of-service condition.
This issue affects MySQL 5.x; other versions may also be vulnerable.
Exploit / POC
MySQL 5.x Unspecified Buffer Overflow Vulnerability
A working commercial exploit is available through Intevydis. This exploit is not otherwise publicly available or known to be circulating in the wild.
A working commercial exploit is available through Intevydis. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
MySQL 5.x Unspecified Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
MySQL 5.x Unspecified Buffer Overflow Vulnerability
References:
References:
- MySQL Homepage (Oracle)
- VulnDisco Pack Professional (Intevydis)