2.1
CVSSv2

CVE-2007-1420

Published: 12/03/2007 Updated: 17/12/2019
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 215
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

MySQL 5.x prior to 5.0.36 allows local users to cause a denial of service (database crash) by performing information_schema table subselects and using ORDER BY to sort a single-row result, which prevents certain structure elements from being initialized and triggers a NULL dereference in the filesort function.

Vulnerable Product Search on Vulmon Subscribe to Product

mysql mysql 5.0.15

oracle mysql 5.0.7

oracle mysql 5.0.6

oracle mysql 5.0.41

mysql mysql 5.0.16

oracle mysql 5.0.32

mysql mysql

mysql mysql 5.0.0

mysql mysql 5.0.10

mysql mysql 5.0.5

mysql mysql 5.0.4

mysql mysql 5.0.24

mysql mysql 5.0.30

mysql mysql 5.0.2

mysql mysql 5.0.20

mysql mysql 5.0.17

mysql mysql 5.0.1

mysql mysql 5.0.3

Vendor Advisories

Stefan Streichbier and B Mueller of SEC Consult discovered that MySQL subselect queries using “ORDER BY” could be made to crash the MySQL server An attacker with access to a MySQL instance could cause an intermitant denial of service ...

Exploits

source: wwwsecurityfocuscom/bid/22900/info MySQL is prone to a remote denial-of-service vulnerability because it fails to handle certain select statements to database metadata An attacker can exploit this issue to crash the application, denying access to legitimate users The attacker may also be able to execute arbitrary code, but this ...