PT-2011-1435 · Oracle+1 · Mysql Server+1

Published

2010-11-03

·

Updated

2019-12-17

·

CVE-2010-3833

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions MySQL versions 5.0 before 5.0.92 MySQL versions 5.1 before 5.1.51 MySQL versions 5.5 before 5.5.6
Description The issue allows remote attackers to cause a denial of service, resulting in a server crash, by providing crafted arguments to extreme-value functions such as LEAST and GREATEST. This is related to the handling of type errors and the KILL BAD DATA mechanism in the context of a "CREATE TABLE ... SELECT" statement.
Recommendations For MySQL versions 5.0 before 5.0.92, update to version 5.0.92 or later. For MySQL versions 5.1 before 5.1.51, update to version 5.1.51 or later. For MySQL versions 5.5 before 5.5.6, update to version 5.5.6 or later.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-3833
DSA-2143-1
RHSA-2010:0825
RHSA-2010_0825
RHSA-2011:0164
RHSA-2011_0164

Affected Products

Mysql Server
Red Hat