Oracle MySQL Server Multiple Vulnerabilities
Last Update Date:
4 Dec 2012 11:15
Release Date:
4 Dec 2012
5507
Views
RISK: Medium Risk
TYPE: Servers - Database Servers
Multiple vulnerabilities have been identified in MySQL, which can be exploited by malicious users to cause a DoS (Denial of Service) and compromise a vulnerable system and by malicious people to conduct brute force attacks.
- An error when processing a database name within certain functions when checking access rights can be exploited to cause a stack-based buffer overflow.
- An error when deleting a table can be exploited to cause a heap-based buffer overflow.
- An error when handling the COM_BINLOG_DUMP command can be exploited to crash the daemon.
- An error when handling authentication errors can be exploited to enumerate valid user accounts.
Successful exploitation of vulnerabilities #1 and #2 may allow execution of arbitrary code.
Note: No patch is currently avaliable
Impact
- Denial of Service
- Remote Code Execution
- Information Disclosure
System / Technologies affected
- MySQL 5.x
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- No patch is currently avaliable
Vulnerability Identifier
Source
Related Link
Share with