Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2009-4019

Опубликовано: 04 нояб. 2009
Источник: redhat
CVSS2: 2.7
EPSS Низкий

Описание

mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of certain SELECT statements with subqueries, and does not (2) preserve certain null_value flags during execution of statements that use the GeomFromWKB function, which allows remote authenticated users to cause a denial of service (daemon crash) via a crafted statement.

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=540906mysql: DoS (crash) when comparing GIS items from subquery and when handling subqueires in WHERE and assigning a SELECT result to a @variable

EPSS

Процентиль: 91%
0.07665
Низкий

2.7 Low

CVSS2

Связанные уязвимости

ubuntu
больше 15 лет назад

mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of certain SELECT statements with subqueries, and does not (2) preserve certain null_value flags during execution of statements that use the GeomFromWKB function, which allows remote authenticated users to cause a denial of service (daemon crash) via a crafted statement.

nvd
больше 15 лет назад

mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of certain SELECT statements with subqueries, and does not (2) preserve certain null_value flags during execution of statements that use the GeomFromWKB function, which allows remote authenticated users to cause a denial of service (daemon crash) via a crafted statement.

debian
больше 15 лет назад

mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not ( ...

github
около 3 лет назад

mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of certain SELECT statements with subqueries, and does not (2) preserve certain null_value flags during execution of statements that use the GeomFromWKB function, which allows remote authenticated users to cause a denial of service (daemon crash) via a crafted statement.

oracle-oval
больше 15 лет назад

ELSA-2010-0109: mysql security update (MODERATE)

EPSS

Процентиль: 91%
0.07665
Низкий

2.7 Low

CVSS2