PT-2002-2289 · Oracle · Mysql Server
Publicado
2002-12-23
·
Atualizado
2019-10-07
·
CVE-2002-1374
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
MySQL versions 3.x through 3.23.54
MySQL versions 4.x through 4.0.6
Description
The issue allows remote attackers to gain privileges via a brute force attack. This is possible because the COM CHANGE USER command in the affected software only compares the provided password against the first character of the real password when a one-character password is used.
Recommendations
For MySQL versions 3.x through 3.23.54, update to version 3.23.54 or later.
For MySQL versions 4.x through 4.0.6, update to version 4.0.6 or later.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Mysql Server