PT-2009-4863 · Oracle+1 · Mysql Server+1

Published

2009-07-13

·

Updated

2019-12-17

·

CVE-2009-2446

CVSS v2.0

8.5

High

VectorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions MySQL versions 4.0.0 through 5.0.83
Description The issue is related to multiple format string vulnerabilities in the dispatch command function. These vulnerabilities can be exploited by remote authenticated users, potentially causing a denial of service (daemon crash) and possibly having other unspecified impacts. The exploitation occurs through format string specifiers in a database name in specific requests, including COM CREATE DB and COM DROP DB requests.
Recommendations For MySQL versions 4.0.0 through 5.0.83, update to a version that contains a fix for this issue to prevent potential exploitation.

Exploit

Fix

DoS

Use of Externally-Controlled Format String

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-2446
DSA-1877-1
RHSA-2009:1289
RHSA-2009:1461
RHSA-2009_1289
RHSA-2010:0110
RHSA-2010_0110

Affected Products

Mysql Server
Red Hat