PT-2006-7517 · Oracle+1 · Mysql Server+1

Masaaki Hirose

·

Publicado

2006-12-31

·

Atualizado

2018-10-17

·

CVE-2006-7232

CVSS v2.0

3.5

Baixa

VetorAV:N/AC:M/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: MySQL versions 5.0.x through 5.0.31 MySQL versions 5.1.x through 5.1.13
Description: The issue allows remote authenticated users to cause a denial of service, resulting in a crash, by using an EXPLAIN SELECT FROM statement on the INFORMATION SCHEMA table with an ORDER BY clause.
Recommendations: For MySQL versions 5.0.x through 5.0.31, update to version 5.0.32 or later. For MySQL versions 5.1.x through 5.1.13, update to version 5.1.14 or later.

Correção

DoS

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2006-7232
RHSA-2008:0364
RHSA-2008_0364

Produtos afetados

Mysql Server
Red Hat