Skip to main content

MySQL Remote Code Execution Vulnerability

Last Update Date: 4 Feb 2014 16:15 Release Date: 4 Feb 2014 3890 Views

RISK: High Risk

TYPE: Servers - Database Servers

TYPE: Database Servers

A vulnerability was reported in MySQL, which can be exploited by a remote user to execute arbitrary code on the target system.

 

A remote server can send a specially crafted server version number string to trigger a buffer overflow in 'client/mysql.cc' and cause the client to crash or potentially execute arbitrary code on the target system.

 

Note: Vendor patch is currently unavailable.


Impact

  • Remote Code Execution

System / Technologies affected

  • MySQL

Solutions

  • Vendor patch is currently unavailable.

Vulnerability Identifier


Source


Related Link