PT-2009-4863 · Oracle+1 · Mysql Server+1

Publicado

2009-07-13

·

Atualizado

2019-12-17

·

CVE-2009-2446

CVSS v2.0

8.5

Alta

VetorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions MySQL versions 4.0.0 through 5.0.83
Description The issue is related to multiple format string vulnerabilities in the dispatch command function. These vulnerabilities can be exploited by remote authenticated users, potentially causing a denial of service (daemon crash) and possibly having other unspecified impacts. The exploitation occurs through format string specifiers in a database name in specific requests, including COM CREATE DB and COM DROP DB requests.
Recommendations For MySQL versions 4.0.0 through 5.0.83, update to a version that contains a fix for this issue to prevent potential exploitation.

Exploit

Correção

DoS

Use of Externally-Controlled Format String

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-2446
DSA-1877-1
RHSA-2009:1289
RHSA-2009:1461
RHSA-2009_1289
RHSA-2010:0110
RHSA-2010_0110

Produtos afetados

Mysql Server
Red Hat