Korean
<< Back
VID 25126
Severity 40
Port 3306
Protocol TCP
Class DB
Detailed Description The version of MySQL Community Server installed on the remote host is earlier than 5.1.67 and affected by vulnerabilities in the following components :
- Information Schema (DoS)
- InnoDB (DoS)
- Server (DoS)
- Server Locking (DoS)
- Server Optimizer (DoS)
- Server Privileges (DoS)
- Server Replication (It discloses sensitive information and manipulates data)

* Note: This check solely relied on the banner of the remote MySQL server to assess this vulnerability, so this might be a false positive.

* References:
http://dev.mysql.com/doc/refman/5.1/en/news-5-1-67.html
http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html#AppendixMSQL

* Platforms Affected:
MySQL versions prior to 5.1.67
Any operating system Any version
Recommendation Upgrade to the latest version of MySQL (5.1.67 or later), available from the MySQL Web site at http://www.mysql.com/
Related URL CVE-2012-0572,CVE-2012-0574,CVE-2012-1702,CVE-2012-1705,CVE-2012-5611,CVE-2013-0375,CVE-2013-0383,CVE-2013-0384,CVE-2013-0385,CVE-2013-0389 (CVE)
Related URL 56769,57385,57388,57391,57405,57410,57412,57414,57416,57417 (SecurityFocus)
Related URL (ISS)