MySQL Anonymous Login Handshake Remote Information Disclosure

This script is Copyright (C) 2006-2011 Tenable Network Security, Inc.

Synopsis :

The remote database server is affected by an information disclosure

Description :

The MySQL database server on the remote host reads from uninitialized
memory when processing a specially crafted login packet. An
unauthenticated attacker may be able to exploit this flaw to obtain
sensitive information from the affected host as returned in an error

See also :

Solution :

Upgrade to MySQL 4.0.27 / 4.1.19 / 5.0.21 / 5.1.10 or later.

Risk factor :

Medium / CVSS Base Score : 5.0
CVSS Temporal Score : 4.1
Public Exploit Available : true

Family: Databases

Nessus Plugin ID: 21632 ()

Bugtraq ID: 17780

CVE ID: CVE-2006-1516