5
CVSSv2

CVE-2006-1517

Published: 05/05/2006 Updated: 17/12/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote malicious users to obtain sensitive information via a COM_TABLE_DUMP request with an incorrect packet length, which includes portions of memory in an error message.

Vulnerable Product Search on Vulmon Subscribe to Product

oracle mysql 4.0.0

oracle mysql 4.0.1

oracle mysql 4.0.15

oracle mysql 4.0.16

oracle mysql 4.0.24

oracle mysql 4.0.25

oracle mysql 4.0.7

oracle mysql 4.1.0

mysql mysql 4.1.10

oracle mysql 4.1.17

oracle mysql 4.1.18

oracle mysql 4.1.7

mysql mysql 4.1.8

oracle mysql 5.0.11

oracle mysql 5.0.12

mysql mysql 5.0.3

oracle mysql 5.0.3

oracle mysql 4.0.13

oracle mysql 4.0.14

oracle mysql 4.0.20

oracle mysql 4.0.21

oracle mysql 4.0.10

oracle mysql 4.0.11

oracle mysql 4.0.17

oracle mysql 4.0.18

oracle mysql 4.0.26

oracle mysql 4.0.3

oracle mysql 4.0.8

oracle mysql 4.1.11

oracle mysql 4.1.2

mysql mysql 4.1.3

oracle mysql 4.1.9

oracle mysql 5.0.13

oracle mysql 5.0.14

mysql mysql 5.0.15

mysql mysql 5.0.4

mysql mysql 5.0.5

oracle mysql 4.0.23

oracle mysql 4.0.5a

oracle mysql 4.0.6

mysql mysql 4.1.0

mysql mysql 4.1.15

oracle mysql 4.1.16

oracle mysql 4.1.5

oracle mysql 4.1.6

mysql mysql 5.0.1

mysql mysql 5.0.10

oracle mysql 5.0.18

mysql mysql 5.0.2

oracle mysql 5.0.8

oracle mysql 5.0.9

oracle mysql 4.0.12

oracle mysql 4.0.19

oracle mysql 4.0.2

oracle mysql 4.0.4

oracle mysql 4.0.5

oracle mysql 4.0.9

mysql mysql 4.1.12

mysql mysql 4.1.13

mysql mysql 4.1.14

oracle mysql 4.1.3

oracle mysql 4.1.4

oracle mysql 5.0.0

mysql mysql 5.0.16

mysql mysql 5.0.17

oracle mysql 5.0.6

oracle mysql 5.0.7

Vendor Advisories

Stefano Di Paola discovered an information leak in the login packet parser By sending a specially crafted malformed login packet, a remote attacker could exploit this to read a random piece of memory, which could potentially reveal sensitive data (CVE-2006-1516) ...
Several vulnerabilities have been discovered in MySQL, a popular SQL database The Common Vulnerabilities and Exposures Project identifies the following problems: CVE-2006-0903 Improper handling of SQL queries containing the NULL character allows local users to bypass logging mechanisms CVE-2006-1516 Usernames without a trailing null ...
Several vulnerabilities have been discovered in MySQL, a popular SQL database The Common Vulnerabilities and Exposures Project identifies the following problems: CVE-2006-0903 Improper handling of SQL queries containing the NULL character allows local users to bypass logging mechanisms CVE-2006-1516 Usernames without a trailing null ...
Several vulnerabilities have been discovered in MySQL, a popular SQL database The Common Vulnerabilities and Exposures Project identifies the following problems: CVE-2006-0903 Improper handling of SQL queries containing the NULL character allows local users to bypass logging mechanisms CVE-2006-1516 Usernames without a trailing null ...

References

NVD-CWE-Otherhttp://www.wisec.it/vulns.php?page=8http://dev.mysql.com/doc/refman/5.0/en/news-5-0-21.htmlhttp://bugs.debian.org/cgi-bin/bugreport.cgi?bug=365939http://securitytracker.com/id?1016016http://secunia.com/advisories/19929http://www.securityfocus.com/bid/17780http://secunia.com/advisories/20002http://www.gentoo.org/security/en/glsa/glsa-200605-13.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2006:084http://www.osvdb.org/25228http://secunia.com/advisories/20073http://secunia.com/advisories/20076http://www.debian.org/security/2006/dsa-1071http://www.trustix.org/errata/2006/0028http://secunia.com/advisories/20223http://www.debian.org/security/2006/dsa-1073http://secunia.com/advisories/20241http://secunia.com/advisories/20253http://www.debian.org/security/2006/dsa-1079http://secunia.com/advisories/20333http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.599377http://www.novell.com/linux/security/advisories/2006-06-02.htmlhttp://secunia.com/advisories/20424http://secunia.com/advisories/20457http://www.redhat.com/support/errata/RHSA-2006-0544.htmlhttp://secunia.com/advisories/20625http://lists.suse.com/archive/suse-security-announce/2006-Jun/0011.htmlhttp://secunia.com/advisories/20762http://docs.info.apple.com/article.html?artnum=305214http://secunia.com/advisories/24479http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.htmlhttp://www.us-cert.gov/cas/techalerts/TA07-072A.htmlhttp://securityreason.com/securityalert/839http://sunsolve.sun.com/search/document.do?assetkey=1-26-236703-1http://secunia.com/advisories/29847http://www.vupen.com/english/advisories/2007/0930http://www.vupen.com/english/advisories/2006/1633http://www.vupen.com/english/advisories/2008/1326/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/26228https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11036https://usn.ubuntu.com/283-1/http://www.securityfocus.com/archive/1/434164/100/0/threadedhttp://www.securityfocus.com/archive/1/432734/100/0/threadedhttps://usn.ubuntu.com/283-1/https://nvd.nist.gov