Korean
<< Back
VID 25176
Severity 30
Port 3306
Protocol TCP
Class DB
Detailed Description The version of MySQL 5.5 installed on the remote host is earlier than 5.5.47 and is, therefore, affected by a denial of service vulnerability due to repeatedly executing a prepared statement when the default database has been changed. An authenticated, remote attacker can exploit this to cause the server to exit.

* Note: This check solely relied on the banner of the remote MySQL server to assess this vulnerability, so this might be a false positive.

* References:
http://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-47.html

* Platforms Affected:
MySQL versions 5.5 prior to 5.5.47
Any operating system Any version
Recommendation Upgrade to the latest version of MySQL (5.5.47 or later), available from the MySQL Download Web site at http://dev.mysql.com/downloads/
Related URL (CVE)
Related URL (SecurityFocus)
Related URL (ISS)