MySQL Community Server < 5.1.49 Multiple Vulnerabilities

This script is Copyright (C) 2010-2014 Tenable Network Security, Inc.


Synopsis :

The remote database server is affected by multiple vulnerabilities.

Description :

The version of MySQL Community Server installed on the remote host is
earlier than 5.1.49 and thus potentially affected by multiple
vulnerabilities:

- DDL statements could cause the server to crash. (55039)

- Joins involving a table with a unique SET column could
cause the server to crash. (54575)

- Incorrect handling of NULL arguments for IN or CASE
operations involving the WITH ROLLUP modifier could
cause the server to crash. (54477)

- A malformed argument to the BINLOG statement could
cause the server to crash. (54393)

- Using TEMPORARY InnoDB tables with nullable columns
could cause the server to crash. (54044)

- Alternate reads with two indexes on a table using the
HANDLER interface could cause the server to crash.
(54007)

- Using EXPLAIN with queries of the form SELECT ... UNION
... ORDER BY (SELECT ... WHERE ...) could cause the
server to crash. (52711)

- LOAD DATA INFILE did not check for SQL errors sent and
even if errors were already reported, it sent an OK
packet. Also, an assert was sometimes raised when it
should not have been relating to client-server protocol
checking in debug servers. (52512)

See also :

http://bugs.mysql.com/bug.php?id=55039
http://bugs.mysql.com/bug.php?id=55475
http://bugs.mysql.com/bug.php?id=54477
http://bugs.mysql.com/bug.php?id=54393
http://bugs.mysql.com/bug.php?id=54044
http://bugs.mysql.com/bug.php?id=54007
http://bugs.mysql.com/bug.php?id=52711
http://bugs.mysql.com/bug.php?id=52512
http://dev.mysql.com/doc/refman/5.1/en/news-5-1-49.html

Solution :

Upgrade to MySQL Community Server 5.1.49 or later.

Risk factor :

Medium / CVSS Base Score : 4.0
(CVSS2#AV:N/AC:L/Au:S/C:N/I:N/A:P)
CVSS Temporal Score : 3.3
(CVSS2#E:F/RL:OF/RC:C)
Public Exploit Available : true