PT-2011-1440 · Oracle+1 · Mysql Server+1

Published

2010-11-03

·

Updated

2019-12-17

·

CVE-2010-3838

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions MySQL versions 5.0 before 5.0.92 MySQL versions 5.1 before 5.1.51 MySQL versions 5.5 before 5.5.6
Description The issue allows remote authenticated users to cause a denial of service, resulting in a server crash. This can be achieved by crafting a query that utilizes the GREATEST or LEAST function with a mixed list of numeric and LONGBLOB arguments. The problem arises from the improper handling of the function's result when it is processed using an intermediate temporary table.
Recommendations For MySQL versions 5.0 before 5.0.92, update to version 5.0.92 or later. For MySQL versions 5.1 before 5.1.51, update to version 5.1.51 or later. For MySQL versions 5.5 before 5.5.6, update to version 5.5.6 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2010-3838
DSA-2143-1
RHSA-2010:0825
RHSA-2010_0825
RHSA-2011:0164
RHSA-2011_0164

Affected Products

Mysql Server
Red Hat