CVE-2006-1516

MySQL <5.0.20 - Memory Corruption

Title source: llm

Description

The check_connection function in sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attackers to read portions of memory via a username without a trailing null byte, which causes a buffer over-read.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Stefano Di Paola · cremotelinux
https://www.exploit-db.com/exploits/1742

References (42)

... and 22 more

Scores

EPSS 0.8233
EPSS Percentile 99.2%

Details

Status published
Products (46)
mysql/mysql 4.1.0
mysql/mysql 4.1.3
mysql/mysql 4.1.8
mysql/mysql 4.1.10
mysql/mysql 4.1.12
mysql/mysql 4.1.13
mysql/mysql 4.1.14
mysql/mysql 4.1.15
mysql/mysql 5.0.1
mysql/mysql 5.0.2
... and 36 more
Published May 05, 2006
Tracked Since Feb 18, 2026