CVE-2003-1331

high

Description

Stack-based buffer overflow in the mysql_real_connect function in the MySql client library (libmysqlclient) 4.0.13 and earlier allows local users to execute arbitrary code via a long socket name, a different vulnerability than CVE-2001-1453.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/12337

http://www.securityfocus.com/bid/7887

http://archives.neohapsis.com/archives/fulldisclosure/2003-q2/1303.html

Details

Source: Mitre, NVD

Published: 2003-12-31

Updated: 2019-10-07

Risk Information

CVSS v2

Base Score: 4

Vector: CVSS2#AV:N/AC:H/Au:N/C:N/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High