CVE-2010-1849

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

The my_net_skip_rest function in sql/net_serv.cc in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by sending a large number of packets that exceed the maximum length.

References

http://bugs.mysql.com/bug.php?id=50974

http://dev.mysql.com/doc/refman/5.0/en/news-5-0-91.html

http://dev.mysql.com/doc/refman/5.1/en/news-5-1-47.html

http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html

http://lists.mysql.com/commits/106060

http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html

http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00005.html

http://securitytracker.com/id?1024032

http://support.apple.com/kb/HT4435

http://www.mandriva.com/security/advisories?name=MDVSA-2010:107

http://www.ubuntu.com/usn/USN-1397-1

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7328

Details

Source: MITRE

Published: 2010-06-08

Updated: 2019-12-17

Risk Information

CVSS v2

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:mysql:mysql:5.0.0:*:*:*:*:*:*:*

cpe:2.3:a:mysql:mysql:5.0.1:*:*:*:*:*:*:*

cpe:2.3:a:mysql:mysql:5.0.2:*:*:*:*:*:*:*

cpe:2.3:a:mysql:mysql:5.0.3:*:*:*:*:*:*:*

cpe:2.3:a:mysql:mysql:5.0.4:*:*:*:*:*:*:*

cpe:2.3:a:mysql:mysql:5.0.5:*:*:*:*:*:*:*

cpe:2.3:a:mysql:mysql:5.0.5.0.21:*:*:*:*:*:*:*

cpe:2.3:a:mysql:mysql:5.0.10:*:*:*:*:*:*:*

cpe:2.3:a:mysql:mysql:5.0.15:*:*:*:*:*:*:*

cpe:2.3:a:mysql:mysql:5.0.16:*:*:*:*:*:*:*

cpe:2.3:a:mysql:mysql:5.0.17:*:*:*:*:*:*:*

cpe:2.3:a:mysql:mysql:5.0.20:*:*:*:*:*:*:*

cpe:2.3:a:mysql:mysql:5.0.24:*:*:*:*:*:*:*

cpe:2.3:a:mysql:mysql:5.0.45b:*:*:*:*:*:*:*

cpe:2.3:a:mysql:mysql:5.0.82:*:*:*:*:*:*:*

cpe:2.3:a:mysql:mysql:5.0.84:*:*:*:*:*:*:*

cpe:2.3:a:mysql:mysql:5.0.87:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.0.0:alpha:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.0.3:beta:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.0.6:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.0.7:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.0.8:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.0.9:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.0.11:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.0.12:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.0.13:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.0.14:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.0.18:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.0.19:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.0.21:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.0.22:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.0.23:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.0.27:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.0.33:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.0.37:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.0.41:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.0.45:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.0.51:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.0.67:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.0.75:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.0.77:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.0.81:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.0.83:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.0.85:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.0.86:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.0.88:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.0.89:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.0.90:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.0.91:*:*:*:*:*:*:*

Configuration 2

OR

cpe:2.3:a:mysql:mysql:5.1.5:*:*:*:*:*:*:*

cpe:2.3:a:mysql:mysql:5.1.23:*:*:*:*:*:*:*

cpe:2.3:a:mysql:mysql:5.1.31:*:*:*:*:*:*:*

cpe:2.3:a:mysql:mysql:5.1.32:*:*:*:*:*:*:*

cpe:2.3:a:mysql:mysql:5.1.34:*:*:*:*:*:*:*

cpe:2.3:a:mysql:mysql:5.1.37:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.1:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.1.1:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.1.2:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.1.3:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.1.4:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.1.6:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.1.7:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.1.8:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.1.9:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.1.10:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.1.11:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.1.12:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.1.13:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.1.14:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.1.15:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.1.16:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.1.17:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.1.30:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.1.33:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.1.35:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.1.36:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.1.38:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.1.39:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.1.40:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.1.41:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.1.42:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.1.43:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.1.44:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.1.45:*:*:*:*:*:*:*

cpe:2.3:a:oracle:mysql:5.1.46:*:*:*:*:*:*:*

Tenable Plugins

View all (22 total)

IDNameProductFamilySeverity
68457Oracle Linux 5 : mysql (ELSA-2012-0127)NessusOracle Linux Local Security Checks
medium
58325Ubuntu 8.04 LTS / 10.04 LTS / 10.10 / 11.04 / 11.10 : mysql-5.1, mysql-dfsg-5.0, mysql-dfsg-5.1 vulnerabilities (USN-1397-1)NessusUbuntu Local Security Checks
high
57951CentOS 5 : mysql (CESA-2012:0127)NessusCentOS Local Security Checks
medium
57930RHEL 5 : mysql (RHSA-2012:0127)NessusRed Hat Local Security Checks
medium
57446GLSA-201201-02 : MySQL: Multiple vulnerabilitiesNessusGentoo Local Security Checks
high
50936SuSE 11 / 11.1 Security Update : MySQL (SAT Patch Numbers 3220 / 3243)NessusSuSE Local Security Checks
medium
800791Mac OS X 10.6 < 10.6.5 Multiple VulnerabilitiesLog Correlation EngineOperating System Detection
high
5705Mac OS X 10.6 < 10.6.5 Multiple VulnerabilitiesNessus Network MonitorGeneric
critical
50549Mac OS X Multiple Vulnerabilities (Security Update 2010-007)NessusMacOS X Local Security Checks
high
50548Mac OS X 10.6.x < 10.6.5 Multiple VulnerabilitiesNessusMacOS X Local Security Checks
critical
50523SuSE9 Security Update : MySQL (YOU Patch Number 12661)NessusSuSE Local Security Checks
medium
50021SuSE 10 Security Update : MySQL (ZYPP Patch Number 7172)NessusSuSE Local Security Checks
medium
50016openSUSE Security Update : libmysqlclient-devel (openSUSE-SU-2010:0730-1)NessusSuSE Local Security Checks
medium
50010openSUSE Security Update : libmysqlclient-devel (openSUSE-SU-2010:0731-1)NessusSuSE Local Security Checks
medium
47523Fedora 11 : mysql-5.1.47-1.fc11 (2010-9061)NessusFedora Local Security Checks
medium
47522Fedora 12 : mysql-5.1.47-1.fc12 (2010-9053)NessusFedora Local Security Checks
medium
47519Fedora 13 : mysql-5.1.47-1.fc13 (2010-9016)NessusFedora Local Security Checks
medium
5587MySQL Community Server < 5.1.47 / 5.0.91 Multiple VulnerabilitiesNessus Network MonitorDatabase
medium
46855Ubuntu 6.06 LTS / 8.04 LTS / 9.04 / 9.10 / 10.04 LTS : mysql-dfsg-5.0, mysql-dfsg-5.1 vulnerabilities (USN-950-1)NessusUbuntu Local Security Checks
medium
46832Debian DSA-2057-1 : mysql-dfsg-5.0 - several vulnerabilitiesNessusDebian Local Security Checks
medium
46726Mandriva Linux Security Advisory : mysql (MDVSA-2010:107)NessusMandriva Local Security Checks
medium
46702MySQL Community Server < 5.1.47 / 5.0.91 Multiple VulnerabilitiesNessusDatabases
medium