PT-2005-1748 · Mysql Server+1 · Mysql Server+1

Stefano Di Paola

·

Publicado

2005-03-11

·

Atualizado

2019-12-17

·

CVE-2005-0709

CVSS v2.0

4.6

Média

VetorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MySQL versions 4.0.23 and earlier MySQL versions 4.1.x up to 4.1.10
Description The issue allows remote authenticated users with INSERT and DELETE privileges to execute arbitrary code by using CREATE FUNCTION to access libc calls, such as strcat, on exit, and exit.
Recommendations For MySQL versions 4.0.23 and earlier, update to a version later than 4.0.23 to resolve the issue. For MySQL versions 4.1.x up to 4.1.10, update to a version later than 4.1.10 to resolve the issue. As a temporary workaround, consider restricting the use of the CREATE FUNCTION statement to minimize the risk of exploitation.

Exploit

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2005-0709
DSA-707-1
RHSA-2005:334
RHSA-2005_334

Produtos afetados

Mysql Server
Red Hat