Hughes Technologies Mini SQL Denial of Service Vulnerability
BID:3742
Info
Hughes Technologies Mini SQL Denial of Service Vulnerability
| Bugtraq ID: | 3742 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2001-1225 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 26 2001 12:00AM |
| Updated: | Jul 11 2009 09:06AM |
| Credit: | Discovered by Lesha Pavlov <[email protected]> and posted to the BugTraq mailing list on December 26, 2001. |
| Vulnerable: |
Hughes Technologies Mini SQL (mSQL) 2.0.12 Hughes Technologies Mini SQL (mSQL) 2.0.11 Hughes Technologies Mini SQL (mSQL) 2.0.10 |
| Not Vulnerable: | |
Discussion
Hughes Technologies Mini SQL Denial of Service Vulnerability
Mini SQL is a lightweight database system. It was designed to provide rapid access to relatively small and simple data sets with minimal overhead and hardware requirements.
A vulnerability exists in Mini SQL 2.0. A user able to connect to the database and create tables may construct a table with an extremely large char array for one of the columns. When a select statement is issued against this table, the database process will crash. This results in a denial of service condition.
Earlier versions of Mini SQL may share this vulnerability.
Mini SQL is a lightweight database system. It was designed to provide rapid access to relatively small and simple data sets with minimal overhead and hardware requirements.
A vulnerability exists in Mini SQL 2.0. A user able to connect to the database and create tables may construct a table with an extremely large char array for one of the columns. When a select statement is issued against this table, the database process will crash. This results in a denial of service condition.
Earlier versions of Mini SQL may share this vulnerability.
Exploit / POC
Hughes Technologies Mini SQL Denial of Service Vulnerability
No exploit code is required to take advantage of this issue.
No exploit code is required to take advantage of this issue.
Solution / Fix
Hughes Technologies Mini SQL Denial of Service Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Hughes Technologies Mini SQL Denial of Service Vulnerability
References:
References:
- MSQL Product Information (Hughes Technology)