• Tenable
  • CVEs
  • Settings
    Links
    Tenable.io Tenable Community & Support Tenable University
    Severity
    Theme
  • Tenable
  • Links
  • Tenable.io
  • Tenable Community & Support
  • Tenable University
  • Settings
  • Severity
  • Theme
  • Newest
  • Updated
  • Search
  • Newest
  • Updated
  • Search
  1. CVEs
  2. CVE-2010-3679
  1. CVEs

CVE-2010-3679

medium
  • Information
  • CPEs
  • Plugins

Description

Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (mysqld daemon crash) via certain arguments to the BINLOG command, which triggers an access of uninitialized memory, as demonstrated by valgrind.

References

http://bugs.mysql.com/bug.php?id=54393

http://dev.mysql.com/doc/refman/5.1/en/news-5-1-49.html

http://secunia.com/advisories/42936

http://www.mandriva.com/security/advisories?name=MDVSA-2010:155

http://www.mandriva.com/security/advisories?name=MDVSA-2011:012

http://www.openwall.com/lists/oss-security/2010/09/28/10

http://www.redhat.com/support/errata/RHSA-2011-0164.html

http://www.securityfocus.com/bid/42638

http://www.ubuntu.com/usn/USN-1017-1

http://www.ubuntu.com/usn/USN-1397-1

http://www.vupen.com/english/advisories/2011/0133

http://www.vupen.com/english/advisories/2011/0170

https://bugzilla.redhat.com/show_bug.cgi?id=628062

https://exchange.xforce.ibmcloud.com/vulnerabilities/64687

Details

Source: MITRE

Published: 2011-01-11

Updated: 2019-12-17

Type: CWE-399

Risk Information

CVSS v2

Base Score: 4

Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 8

Severity: MEDIUM

  • Tenable.com
  • Community & Support
  • Documentation
  • Education
  • © 2022 Tenable®, Inc. All Rights Reserved
  • Privacy Policy
  • Legal
  • 508 Compliance