LWN.net Logo

mysql: denial of service

Package(s):mysql CVE #(s):CVE-2009-4019
Created:December 11, 2009 Updated:May 10, 2010
Description: From the CVE entry: mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of certain SELECT statements with subqueries, and does not (2) preserve certain null_value flags during execution of statements that use the GeomFromWKB function, which allows remote authenticated users to cause a denial of service (daemon crash) via a crafted statement.
Alerts:
SuSE SUSE-SR:2010:011 2010-05-10
SuSE SUSE-SR:2010:007 2010-03-30
rPath rPSA-2010-0014-1 2010-03-07
Mandriva MDVSA-2010:012 2010-01-17
Mandriva MDVSA-2010:011 2010-01-17
Red Hat RHSA-2010:0109-01 2010-02-16
Fedora FEDORA-2009-13466 2009-12-22
Fedora FEDORA-2009-13504 2009-12-22
Fedora FEDORA-2009-12180 2009-11-25
CentOS CESA-2010:0109 2010-03-01
Debian DSA-1997-1 2010-02-14
Ubuntu USN-897-1 2010-02-10
Gentoo 201201-02 2012-01-05
Ubuntu USN-1397-1 2012-03-12

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds