4
CVSSv2

CVE-2007-2583

Published: 10/05/2007 Updated: 08/11/2021
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 405
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

The in_decimal::set function in item_cmpfunc.cc in MySQL prior to 5.0.40, and 5.1 prior to 5.1.18-beta, allows context-dependent malicious users to cause a denial of service (crash) via a crafted IF clause that results in a divide-by-zero error and a NULL pointer dereference.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

oracle mysql

debian debian linux 3.1

debian debian linux 4.0

canonical ubuntu linux 6.06

canonical ubuntu linux 6.10

canonical ubuntu linux 7.04

Vendor Advisories

Neil Kettle discovered that MySQL could be made to dereference a NULL pointer and divide by zero An authenticated user could exploit this with a crafted IF clause, leading to a denial of service (CVE-2007-2583) ...
Several vulnerabilities have been found in the MySQL database packages with implications ranging from unauthorized database modifications to remotely triggered server crashes The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2007-2583 The in_decimal::set function in item_cmpfunccc in MySQL before 5040 al ...

Exploits

source: wwwsecurityfocuscom/bid/23911/info MySQL is prone to a remote denial-of-service vulnerability because it fails to handle certain specially crafted queries An attacker can exploit this issue to crash the application, denying access to legitimate users NOTE: An attacker must be able to execute arbitrary SELECT statements against ...