Korean
<< Back
VID 25098
Severity 30
Port 3306
Protocol TCP
Class DB
Detailed Description The version of MySQL Community Server installed on the remote host is earlier than 5.1.52 and thus potentially affected by multiple vulnerabilities:

- An error exists in the handling of 'EXPLAIN' for a 'SELECT' statement from a derived table which can cause the server to crash. (54488)
- An error exists in the handling of 'EXPLAIN EXTENDED' when used in some prepared statements, which can cause the server to crash. (54494)
- The server does not check the type of values assigned to items of type 'GeometryCollection'. Such assignments can cause the server to crash. (55531)

* Note: This check solely relied on the banner of the remote MySQL server to assess this vulnerability, so this might be a false positive.

* References:


* Platforms Affected:
MySQL versions prior to 5.1.52
Any operating system Any version
Recommendation Upgrade to the latest version of MySQL (5.1.52 or later), available from the MySQL Web site at http://www.mysql.com/
Related URL (CVE)
Related URL (SecurityFocus)
Related URL (ISS)