MySQL: mysqld DoS (crash) by processing EXPLAIN statements for complex SQL queries (MySQL bug #52711)
Published Jan 11, 2011
4.0
MEDIUMCVSS 2.0
EPSS 11.44%
Description
Oracle MySQL 5.1 before 5.1.49 and 5.0 before 5.0.92 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by using EXPLAIN with crafted "SELECT ... UNION ... ORDER BY (SELECT ... WHERE ...)" statements, which triggers a NULL pointer dereference in the Item_singlerow_subselect::store function.
Affected products
No data.
Configuration 1
- ≤ 5.1.48
- 5.1.23
- 5.1.31
- 5.1.32
- 5.1.34
- 5.1.37
- 5.1.1
- 5.1.2
- 5.1.3
- 5.1.4
- 5.1.10
- 5.1.11
- 5.1.12
- 5.1.13
- 5.1.14
- 5.1.15
- 5.1.16
- 5.1.17
- 5.1.18
- 5.1.19
- 5.1.20
- 5.1.21
- 5.1.22
- 5.1.23
- 5.1.24
- 5.1.25
- 5.1.26
- 5.1.27
- 5.1.28
- 5.1.29
- 5.1.30
- 5.1.31
- 5.1.33
- 5.1.34
- 5.1.35
- 5.1.36
- 5.1.37
- 5.1.38
- 5.1.39
- 5.1.40
- 5.1.40
- 5.1.41
- 5.1.42
- 5.1.43
- 5.1.43
- 5.1.44
- 5.1.45
- 5.1.46
- 5.1.46
- 5.1.47
Configuration 2
- ≤ 5.0.91
- 5.0.0
- 5.0.1
- 5.0.2
- 5.0.10
- 5.0.15
- 5.0.16
- 5.0.17
- 5.0.20
- 5.0.24
- 5.0.30
- 5.0.36
- 5.0.44
- 5.0.54
- 5.0.56
- 5.0.60
- 5.0.66
- 5.0.72
- 5.0.74
- 5.0.82
- 5.0.84
- 5.0.87
- 5.0.28
- 5.0.30
- 5.0.32
- 5.0.34
- 5.0.36
- 5.0.38
- 5.0.40
- 5.0.41
- 5.0.42
- 5.0.44
- 5.0.45
- 5.0.46
- 5.0.48
- 5.0.50
- 5.0.51
- 5.0.51
- 5.0.52
- 5.0.56
- 5.0.58
- 5.0.62
- 5.0.64
- 5.0.66
- 5.0.66
- 5.0.67
- 5.0.68
- 5.0.70
- 5.0.72
- 5.0.74
- 5.0.75
- 5.0.76
- 5.0.77
- 5.0.78
- 5.0.79
- 5.0.80
- 5.0.81
- 5.0.82
- 5.0.83
- 5.0.84
- 5.0.85
- 5.0.86
- 5.0.87
- 5.0.88
- 5.0.89
- 5.0.90
No data.
Red Hat Enterprise Linux 5
mysql-0:5.0.77-4.el5_5.4
Fixed · RHSA-2010:0825
Red Hat Enterprise Linux 6
mysql-0:5.1.52-1.el6_0.1
Fixed · RHSA-2011:0164
Red Hat Enterprise Linux 4
mysql
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | mysql-0:5.0.77-4.el5_5.4 | Fixed | RHSA-2010:0825 |
| Red Hat Enterprise Linux 6 | mysql-0:5.1.52-1.el6_0.1 | Fixed | RHSA-2011:0164 |
| Red Hat Enterprise Linux 4 | mysql | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue did not affect the versions of mysql as shipped with Red Hat Enterprise Linux 3 and 4. This issue was addressed in Red Hat Enterprise Linux 5 via https://rhn.redhat.com/errata/RHSA-2010-0825.html.
References (28)
- http://bugs.mysql.com/bug.php?id=52711 x_refsource_CONFIRMExploitPatch
- http://dev.mysql.com/doc/refman/5.0/en/news-5-0-92.html x_refsource_CONFIRM
- http://dev.mysql.com/doc/refman/5.1/en/news-5-1-49.html x_refsource_CONFIRM
- http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.html vendor-advisoryx_refsource_APPLE
- http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html vendor-advisoryx_refsource_SUSE
- http://secunia.com/advisories/42875 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/42936 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://support.apple.com/kb/HT4723 x_refsource_CONFIRM
- http://www.debian.org/security/2011/dsa-2143 vendor-advisoryx_refsource_DEBIAN
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:155 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:222 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:012 vendor-advisoryx_refsource_MANDRIVA
- http://www.openwall.com/lists/oss-security/2010/09/28/10 mailing-listx_refsource_MLISTExploitPatch
- http://www.redhat.com/support/errata/RHSA-2010-0825.html vendor-advisoryx_refsource_REDHATVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2011-0164.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/bid/42599 vdb-entryx_refsource_BID
- http://www.turbolinux.co.jp/security/2011/TLSA-2011-3j.txt vendor-advisoryx_refsource_TURBO
- http://www.ubuntu.com/usn/USN-1017-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-1397-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vupen.com/english/advisories/2011/0105 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2011/0133 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2011/0170 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2011/0345 vdb-entryx_refsource_VUPENVendor Advisory
- https://access.redhat.com/security/cve/CVE-2010-3682 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=628328 x_refsource_CONFIRMExploitPatchIssue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64684 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2010-3682
- https://www.cve.org/CVERecord?id=CVE-2010-3682
Change history (0)
No recorded changes yet.