Korean
<< Back
VID 25039
Severity 40
Port 3306
Protocol TCP
Class DB
Detailed Description A version of MySQL 4.1.x which is older than version 4.1.5 is running on the host. MySQL 4.1.x prior to 4.1.5 are vulnerable to a buffer overflow in the libmysqlclient. This vulnerability could allow a remote authenticated attacker to execute bulk inserts using specially-crafted prepared statements containing thousands of placeholders and trigger a buffer overflow. The attacker could use this vulnerability to cause a MySQL server to crash or possibly execute arbitrary code with the privileges of the user running the mysqld process.

* Note: This check solely relied on the version number of the remote MySQL server to assess this vulnerability, so this might be a false positive.

* References:
http://bugs.mysql.com/bug.php?id=5194
http://www.securitytracker.com/alerts/2004/Sep/1011408.html

* Platforms Affected:
MySQL AB, MySQL 4.1.x prior to 4.1.5
Unix, Linux Any version
Recommendation Upgrade to the latest version of MySQL (4.1.5 or later), available from the MySQL Web site at http://dev.mysql.com/doc/mysql/en/News-4.1.5.html
Related URL (CVE)
Related URL 11261 (SecurityFocus)
Related URL 17493 (ISS)