Overview
MySQL contains a buffer overflow that may allow a remote, authenticated attacker to execute arbitrary code on a vulnerable server.
Description
MySQL and COM_TABLE_DUMP MySQL is an open-source database system available for Microsoft Windows, Linux, and other UNIX-based operating systems. Command packets are sent to the MySQL server to issue instructions to that server. One such command packet type is COM_TABLE_DUMP, which the MySQL Internals Manual describes as: |
Impact
A remote, authenticated attacker may be able to execute arbitrary code on a MySQL server. |
Solution
Upgrade |
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://secunia.com/advisories/19929/
- http://dev.mysql.com/doc/refman/4.1/en/news-4-0-27.html
- http://dev.mysql.com/doc/refman/4.1/en/news-4-1-19.html
- http://dev.mysql.com/doc/refman/5.0/en/news-5-0-21.html
- http://dev.mysql.com/doc/refman/5.1/en/news-5-1-10.html
- http://downloads.mysql.com/docs/internals-en.pdf
Acknowledgements
This vulnerability was reported by Stefano Di Paola.
This document was written by Jeff Gennari.
Other Information
CVE IDs: | CVE-2006-1518 |
Severity Metric: | 12.33 |
Date Public: | 2006-05-02 |
Date First Published: | 2006-05-05 |
Date Last Updated: | 2006-05-17 12:24 UTC |
Document Revision: | 40 |