LWN.net Logo

mysql: denial of service

Package(s):mysql CVE #(s):CVE-2010-3840
Created:November 4, 2010 Updated:July 19, 2011
Description:

From the Red Hat advisory:

It was found that the MySQL PolyFromWKB() function did not sanity check Well-Known Binary (WKB) data. A remote, authenticated attacker could use specially-crafted WKB data to crash mysqld. This issue only caused a temporary denial of service, as mysqld was automatically restarted after the crash. (CVE-2010-3840)

Alerts:
openSUSE openSUSE-SU-2011:1250-1 2011-11-16
openSUSE openSUSE-SU-2011:0799-1 2011-07-19
openSUSE openSUSE-SU-2011:0774-1 2011-07-19
openSUSE openSUSE-SU-2011:0743-1 2011-07-06
Red Hat RHSA-2011:0164-01 2011-01-18
Debian DSA-2143-1 2011-01-14
Ubuntu USN-1017-1 2010-11-11
Mandriva MDVSA-2010:223 2010-11-09
Mandriva MDVSA-2010:222 2010-11-09
CentOS CESA-2010:0825 2010-11-05
CentOS CESA-2010:0824 2010-11-05
Red Hat RHSA-2010:0825-01 2010-11-03
Red Hat RHSA-2010:0824-01 2010-11-03
Gentoo 201201-02 2012-01-05
Ubuntu USN-1397-1 2012-03-12

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds