bugs.mysql.comConfirmation
http://bugs.mysql.com/47780 CVE-2009-4019
MySQL 6.0.9 - SELECT Statement WHERE Clause Sub-query Denial of Service
Record summary
CVE-2009-4019 has a selected CVSS score of 4.0; EIP currently links 2 catalogued exploits.
Description
mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of certain SELECT statements with subqueries, and does not (2) preserve certain null_value flags during execution of statements that use the GeomFromWKB function, which allows remote authenticated users to cause a denial of service (daemon crash) via a crafted statement.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBMySQL 6.0.9 - SELECT Statement WHERE Clause Sub-query Denial of ServiceExploitDB exploitby Shane BesterNot analyzed1 file
ExploitDBMySQL 6.0.9 - 'GeomFromWKB()' Function First Argument Geometry Value Handling Denial of ServiceExploitDB exploitby Shane BesterNot analyzed1 file
References
Showing 12 of 23bugs.mysql.comConfirmation
http://bugs.mysql.com/48291 dev.mysql.comConfirmation
http://dev.mysql.com/doc/refman/5.0/en/news-5-0-88.html dev.mysql.comConfirmation
http://dev.mysql.com/doc/refman/5.1/en/news-5-1-41.html APPLE-SA-2010-03-29-1Vendor advisory
http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html SUSE-SR:2010:011Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html [oss-security] 20091121 CVE Request - MySQL - 5.0.88mailing list
http://marc.info/?l=oss-security&m=125881733826437&w=2 [oss-security] 20091121 Re: CVE Request - MySQL - 5.0.88mailing list
http://marc.info/?l=oss-security&m=125883754215621&w=2 [oss-security] 20091123 Re: CVE Request - MySQL - 5.0.88mailing list
http://marc.info/?l=oss-security&m=125901161824278&w=2 37717Third-party advisory
http://secunia.com/advisories/37717 38517Third-party advisory
http://secunia.com/advisories/38517 38573Third-party advisory
http://secunia.com/advisories/38573