LWN.net Logo

mysql: multiple vulnerabilities

Package(s):mysql CVE #(s):CVE-2010-3833 CVE-2010-3835 CVE-2010-3836 CVE-2010-3837 CVE-2010-3838 CVE-2010-3839
Created:November 4, 2010 Updated:July 19, 2011
Description:

From the Red Hat advisory:

A flaw was found in the way MySQL processed certain JOIN queries. If a stored procedure contained JOIN queries, and that procedure was executed twice in sequence, it could cause an infinite loop, leading to excessive CPU use (up to 100%). A remote, authenticated attacker could use this flaw to cause a denial of service. (CVE-2010-3839)

A flaw was found in the way MySQL processed queries that provide a mixture of numeric and longblob data types to the LEAST or GREATEST function. A remote, authenticated attacker could use this flaw to crash mysqld. This issue only caused a temporary denial of service, as mysqld was automatically restarted after the crash. (CVE-2010-3838)

A flaw was found in the way MySQL processed PREPARE statements containing both GROUP_CONCAT and the WITH ROLLUP modifier. A remote, authenticated attacker could use this flaw to crash mysqld. This issue only caused a temporary denial of service, as mysqld was automatically restarted after the crash. (CVE-2010-3837)

It was found that MySQL did not properly pre-evaluate LIKE arguments in view prepare mode. A remote, authenticated attacker could possibly use this flaw to crash mysqld. (CVE-2010-3836)

A flaw was found in the way MySQL processed statements that assign a value to a user-defined variable and that also contain a logical value evaluation. A remote, authenticated attacker could use this flaw to crash mysqld. This issue only caused a temporary denial of service, as mysqld was automatically restarted after the crash. (CVE-2010-3835)

A flaw was found in the way MySQL evaluated the arguments of extreme-value functions, such as LEAST and GREATEST. A remote, authenticated attacker could use this flaw to crash mysqld. This issue only caused a temporary denial of service, as mysqld was automatically restarted after the crash. (CVE-2010-3833)

Alerts:
openSUSE openSUSE-SU-2011:1250-1 2011-11-16
openSUSE openSUSE-SU-2011:0799-1 2011-07-19
openSUSE openSUSE-SU-2011:0774-1 2011-07-19
openSUSE openSUSE-SU-2011:0743-1 2011-07-06
Red Hat RHSA-2011:0164-01 2011-01-18
Debian DSA-2143-1 2011-01-14
Ubuntu USN-1017-1 2010-11-11
Mandriva MDVSA-2010:223 2010-11-09
Mandriva MDVSA-2010:222 2010-11-09
CentOS CESA-2010:0825 2010-11-05
Red Hat RHSA-2010:0825-01 2010-11-03
Gentoo 201201-02 2012-01-05
Ubuntu USN-1397-1 2012-03-12

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds