PT-2004-1719 · Oracle · Mysql Server
Chris Anley
·
Publicado
2004-07-08
·
Atualizado
2019-12-17
·
CVE-2004-0627
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
MySQL versions 4.1.x through 4.1.2
MySQL version 5.0
Description
The issue allows remote attackers to bypass authentication. This is possible due to the
check scramble 323 function allowing a zero-length scrambled string.Recommendations
For MySQL versions 4.1.x through 4.1.2, update to version 4.1.3 or later.
For MySQL version 5.0, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the
check scramble 323 function until a patch is available.Exploit
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Mysql Server