Korean
<< Back
VID 25073
Severity 30
Port 3306
Protocol TCP
Class DB
Detailed Description A version of MySQL which is older than 5.1.32 is running on the host. MySQL versions 5.1.x prior to 5.1.32 are denial-of-service vulnerability. Specifically, an authenticated user can cause an assertion failure leading to a server crash by calling 'ExtractValue()' or 'UpdateXML()' using an XPath expression employing a scalar expression as a 'FilterExpr'.

* Note: This check solely relied on the banner of the remote MySQL server to assess this vulnerability, so this might be a false positive.

* References:
http://bugs.mysql.com/bug.php?id=42495
http://dev.mysql.com/doc/refman/5.1/en/news-5-1-32.html

* Platforms Affected:
MySQL AB, MySQL versions 5.1.x prior to 5.1.32
Any operating system Any version
Recommendation Upgrade to the latest version of MySQL (5.1.32 or later), available from the MySQL Web site at http://www.mysql.com/
Related URL CVE-2009-0819 (CVE)
Related URL 33972 (SecurityFocus)
Related URL (ISS)