mysql: over-sized packet denial of service vulnerability
Published Jun 7, 2010
5.0
MEDIUMCVSS 2.0
EPSS 3.72%
Description
The my_net_skip_rest function in sql/net_serv.cc in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by sending a large number of packets that exceed the maximum length.
Affected products
No data.
Configuration 1
- 5.0.0
- 5.0.1
- 5.0.2
- 5.0.3
- 5.0.4
- 5.0.5
- 5.0.5.0.21
- 5.0.10
- 5.0.15
- 5.0.16
- 5.0.17
- 5.0.20
- 5.0.24
- 5.0.45b
- 5.0.82
- 5.0.84
- 5.0.87
- 5.0.0
- 5.0.3
- 5.0.6
- 5.0.7
- 5.0.8
- 5.0.9
- 5.0.11
- 5.0.12
- 5.0.13
- 5.0.14
- 5.0.18
- 5.0.19
- 5.0.21
- 5.0.22
- 5.0.23
- 5.0.27
- 5.0.33
- 5.0.37
- 5.0.41
- 5.0.45
- 5.0.51
- 5.0.67
- 5.0.75
- 5.0.77
- 5.0.81
- 5.0.83
- 5.0.85
- 5.0.86
- 5.0.88
- 5.0.89
- 5.0.90
- 5.0.91
Configuration 2
- 5.1.5
- 5.1.23
- 5.1.31
- 5.1.32
- 5.1.34
- 5.1.37
- 5.1
- 5.1.1
- 5.1.2
- 5.1.3
- 5.1.4
- 5.1.6
- 5.1.7
- 5.1.8
- 5.1.9
- 5.1.10
- 5.1.11
- 5.1.12
- 5.1.13
- 5.1.14
- 5.1.15
- 5.1.16
- 5.1.17
- 5.1.30
- 5.1.33
- 5.1.35
- 5.1.36
- 5.1.38
- 5.1.39
- 5.1.40
- 5.1.41
- 5.1.42
- 5.1.43
- 5.1.44
- 5.1.45
- 5.1.46
No data.
Red Hat Enterprise Linux 5
mysql-0:5.0.95-1.el5_7.1
Fixed · RHSA-2012:0127
Red Hat Enterprise Linux 4
mysql
Will not fix
Red Hat Enterprise Linux 6
mysql
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | mysql-0:5.0.95-1.el5_7.1 | Fixed | RHSA-2012:0127 |
| Red Hat Enterprise Linux 4 | mysql | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | mysql | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue was fixed in mysql packages shipped with Red Hat Enterprise Linux 5 via RHSA-2012:0127. The mysql packages in Red Hat Enterprise Linux 6 include this fix since the initial release of the product.
No CWE recorded.
References (17)
- http://bugs.mysql.com/bug.php?id=50974 x_refsource_CONFIRM
- http://dev.mysql.com/doc/refman/5.0/en/news-5-0-91.html x_refsource_CONFIRM
- http://dev.mysql.com/doc/refman/5.1/en/news-5-1-47.html x_refsource_CONFIRM
- http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html vendor-advisoryx_refsource_APPLE
- http://lists.mysql.com/commits/106060 x_refsource_MISC
- http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00005.html vendor-advisoryx_refsource_SUSE
- http://securitytracker.com/id?1024032 vdb-entryx_refsource_SECTRACK
- http://support.apple.com/kb/HT4435 x_refsource_CONFIRM
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:107 vendor-advisoryx_refsource_MANDRIVA
- http://www.ubuntu.com/usn/USN-1397-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2010-1849 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=592086 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2010-1869 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2010-1849
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7328 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2010-1849
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data