Back

MEDIUM

MySQL: Using an empty binary value leads to server crash

Published Sep 10, 2008

Description

MySQL 5.0 before 5.0.66, 5.1 before 5.1.26, and 6.0 before 6.0.6 does not properly handle a b'' (b single-quote single-quote) token, aka an empty bit-string literal, which allows remote attackers to cause a denial of service (daemon crash) by using this token in a SQL statement.

Affected products

Remediation

Red Hat statement

This issue did not affect MySQL as supplied with Red Hat Enterprise Linux 3 or 4.

Metrics

Weaknesses (1)

References (27)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 10, 2008
Updated Aug 7, 2024
Reserved Sep 9, 2008
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Aug 10, 2008