8.5
CVSSv2

CVE-2009-2446

Published: 13/07/2009 Updated: 17/12/2019
CVSS v2 Base Score: 8.5 | Impact Score: 10 | Exploitability Score: 6.8
VMScore: 855
Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C

Vulnerability Summary

Multiple format string vulnerabilities in the dispatch_command function in libmysqld/sql_parse.cc in mysqld in MySQL 4.0.0 up to and including 5.0.83 allow remote authenticated users to cause a denial of service (daemon crash) and possibly have unspecified other impact via format string specifiers in a database name in a (1) COM_CREATE_DB or (2) COM_DROP_DB request. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

mysql mysql 4.1.8

oracle mysql 4.1.9

oracle mysql 4.1.17

oracle mysql 4.1.16

mysql mysql 4.1.3

oracle mysql 4.1.22

mysql mysql 4.1.0

oracle mysql 4.1.0

mysql mysql 4.1.12

mysql mysql 4.1.13

oracle mysql 4.0.25

oracle mysql 4.0.24

oracle mysql 4.0.6

oracle mysql 4.0.1

oracle mysql 4.0.16

oracle mysql 4.0.17

oracle mysql 5.0.0

oracle mysql 5.0.11

mysql mysql 5.0.1

oracle mysql 5.0.42

mysql mysql 5.0.56

oracle mysql 5.0.32

oracle mysql 5.0.25

oracle mysql 5.0.3

mysql mysql 5.0.3

oracle mysql 5.0.41

mysql mysql 5.0.24

oracle mysql 5.0.27

oracle mysql 4.1.2

mysql mysql 4.1.2

mysql mysql 4.1.23

oracle mysql 4.1.5

oracle mysql 4.1.1

mysql mysql 4.1.10

mysql mysql 4.1.14

mysql mysql 4.1.15

oracle mysql 4.0.4

oracle mysql 4.0.3

oracle mysql 4.0.9

oracle mysql 4.0.8

oracle mysql 4.0.12

oracle mysql 4.0.13

oracle mysql 4.0.2

oracle mysql 4.0.20

oracle mysql 5.0.14

mysql mysql 5.0.15

oracle mysql 5.0.12

oracle mysql 5.0.50

oracle mysql 5.0.45

oracle mysql 5.0.51

oracle mysql 5.0.23

mysql mysql 5.0.5

oracle mysql 5.0.6

oracle mysql 5.0.33

oracle mysql 5.0.21

mysql mysql 5.0.17

oracle mysql 5.0.75

mysql mysql 5.0.82

oracle mysql 4.1.7

oracle mysql 4.1.20

oracle mysql 4.1.6

oracle mysql 4.1.21

oracle mysql 4.0.27

oracle mysql 4.0.26

oracle mysql 4.0.7

oracle mysql 4.0.10

oracle mysql 4.0.0

oracle mysql 4.0.14

oracle mysql 4.0.15

mysql mysql 5.0.0

mysql mysql 5.0.10

oracle mysql 5.0.30

mysql mysql 5.0.54

oracle mysql 5.0.52

oracle mysql 5.0.51a

mysql mysql 5.0.5.0.21

oracle mysql 5.0.37

oracle mysql 5.0.26

mysql mysql 5.0.2

mysql mysql 5.0.20

mysql mysql 5.0.16

mysql mysql 5.0.66

mysql mysql 5.0.60

oracle mysql 5.0.7

oracle mysql 5.0.77

oracle mysql 4.1.19

oracle mysql 4.1.18

oracle mysql 4.1.4

oracle mysql 4.1.3

oracle mysql 4.1.11

oracle mysql 4.0.23

oracle mysql 4.0.21

oracle mysql 4.0.5a

oracle mysql 4.0.5

oracle mysql 4.0.11

oracle mysql 4.0.18

oracle mysql 4.0.19

oracle mysql 5.0.13

mysql mysql 5.0.44

mysql mysql 5.0.30

oracle mysql 5.0.38

mysql mysql 5.0.36

oracle mysql 5.0.9

oracle mysql 5.0.8

mysql mysql 5.0.4

oracle mysql 5.0.22

mysql mysql 5.0.22.1.0.1

oracle mysql 5.0.18

oracle mysql 5.0.19

oracle mysql 5.0.83

oracle mysql 5.0.81

Vendor Advisories

Synopsis Moderate: mysql security update Type/Severity Security Advisory: Moderate Topic Updated mysql packages that fix several security issues are now availablefor Red Hat Enterprise Linux 4This update has been rated as having moderate security impact by the RedHat Security Response Team Descri ...
In MySQL 400 through 5083, multiple format string vulnerabilities in the dispatch_command() function in libmysqld/sql_parsecc in mysqld allow remote authenticated users to cause a denial of service (daemon crash) and potentially the execution of arbitrary code via format string specifiers in a database name in a COM_CREATE_DB or COM_DROP_DB re ...
It was discovered that MySQL could be made to overwrite existing table files in the data directory An authenticated user could use the DATA DIRECTORY and INDEX DIRECTORY options to possibly bypass privilege checks This update alters table creation behaviour by disallowing the use of the MySQL data directory in DATA DIRECTORY and INDEX DIRECTORY o ...

Exploits

source: wwwsecurityfocuscom/bid/35609/info MySQL is prone to multiple format-string vulnerabilities Attackers can leverage these issues to execute arbitrary code within the context of the vulnerable application Failed attacks will likely cause denial-of-service conditions MySQL 400 through 5075 are vulnerable; other versions may ...