| VID |
25039 |
| Severity |
40 |
| Port |
3306 |
| Protocol |
TCP |
| Class |
DB |
| Detailed Description |
A version of MySQL 4.1.x which is older than version 4.1.5 is running on the host. MySQL 4.1.x prior to 4.1.5 are vulnerable to a buffer overflow in the libmysqlclient. This vulnerability could allow a remote authenticated attacker to execute bulk inserts using specially-crafted prepared statements containing thousands of placeholders and trigger a buffer overflow. The attacker could use this vulnerability to cause a MySQL server to crash or possibly execute arbitrary code with the privileges of the user running the mysqld process.
* Note: This check solely relied on the version number of the remote MySQL server to assess this vulnerability, so this might be a false positive.
* References: http://bugs.mysql.com/bug.php?id=5194 http://www.securitytracker.com/alerts/2004/Sep/1011408.html
* Platforms Affected: MySQL AB, MySQL 4.1.x prior to 4.1.5 Unix, Linux Any version |
| Recommendation |
Upgrade to the latest version of MySQL (4.1.5 or later), available from the MySQL Web site at http://dev.mysql.com/doc/mysql/en/News-4.1.5.html |
| Related URL |
(CVE) |
| Related URL |
11261 (SecurityFocus) |
| Related URL |
17493 (ISS) |
|