4
CVSSv2

CVE-2008-3963

Published: 11/09/2008 Updated: 17/12/2019
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 405
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

MySQL 5.0 prior to 5.0.66, 5.1 prior to 5.1.26, and 6.0 prior to 6.0.6 does not properly handle a b'' (b single-quote single-quote) token, aka an empty bit-string literal, which allows remote malicious users to cause a denial of service (daemon crash) by using this token in a SQL statement.

Vulnerable Product Search on Vulmon Subscribe to Product

mysql mysql 5.0.0

mysql mysql 5.0.15

mysql mysql 5.0.2

oracle mysql 5.0.23

oracle mysql 5.0.25

oracle mysql 5.0.26

oracle mysql 5.0.33

oracle mysql 5.0.42

oracle mysql 5.0.38

mysql mysql 5.0.54

oracle mysql 5.0.52

oracle mysql 5.1.3

oracle mysql 5.1.4

oracle mysql 5.1.12

oracle mysql 5.1.17

oracle mysql 5.1.21

oracle mysql 5.1.22

oracle mysql 6.0.2

oracle mysql 6.0.1

oracle mysql 5.0.0

mysql mysql 5.0.10

mysql mysql 5.0.22.1.0.1

mysql mysql 5.0.24

mysql mysql 5.0.3

mysql mysql 5.0.5

mysql mysql 5.0.44

oracle mysql 5.0.50

oracle mysql 5.0.6

mysql mysql 5.0.56

mysql mysql 5.1.5

oracle mysql 5.1.6

oracle mysql 5.1.14

oracle mysql 5.1.11

oracle mysql 5.1.10

oracle mysql 5.1.1

oracle mysql 5.1.20

mysql mysql 5.1.23

mysql mysql 5.0.16

mysql mysql 5.0.20

oracle mysql 5.0.30

mysql mysql 5.0.30

mysql mysql 5.0.36

oracle mysql 5.0.32

mysql mysql 5.0.4

oracle mysql 5.0.51

oracle mysql 5.1.9

oracle mysql 5.1.7

oracle mysql 5.1.2

oracle mysql 5.1.15

oracle mysql 6.0.4

oracle mysql 6.0.3

mysql mysql 5.0.1

mysql mysql 5.0.17

mysql mysql 5.0.5.0.21

oracle mysql 5.0.45

oracle mysql 5.0.41

mysql mysql 5.0.60

oracle mysql 5.1.8

oracle mysql 5.1.13

oracle mysql 5.1.16

oracle mysql 5.1

oracle mysql 5.1.18

oracle mysql 5.1.19

oracle mysql 6.0.0

Vendor Advisories

Multiple vulnerabilities have been identified affecting MySQL, a relational database server, and its associated interactive client application The Common Vulnerabilities and Exposures project identifies the following two problems: CVE-2008-3963 Kay Roepke reported that the MySQL server would not properly handle an empty bit-string literal ...
It was discovered that MySQL could be made to overwrite existing table files in the data directory An authenticated user could use the DATA DIRECTORY and INDEX DIRECTORY options to possibly bypass privilege checks This update alters table creation behaviour by disallowing the use of the MySQL data directory in DATA DIRECTORY and INDEX DIRECTORY o ...

Exploits

source: wwwsecurityfocuscom/bid/31081/info MySQL is prone to a remote denial-of-service vulnerability because it fails to handle empty binary string literals An attacker can exploit this issue to crash the application, denying access to legitimate users This issue affects versions prior to MySQL 5066, 5126, and 606 The follow ...