PT-2004-1719 · Oracle · Mysql Server

Chris Anley

·

Published

2004-07-08

·

Updated

2019-12-17

·

CVE-2004-0627

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions MySQL versions 4.1.x through 4.1.2 MySQL version 5.0
Description The issue allows remote attackers to bypass authentication. This is possible due to the check scramble 323 function allowing a zero-length scrambled string.
Recommendations For MySQL versions 4.1.x through 4.1.2, update to version 4.1.3 or later. For MySQL version 5.0, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the check scramble 323 function until a patch is available.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-0627

Affected Products

Mysql Server