4
CVSSv2

CVE-2009-4019

Published: 30/11/2009 Updated: 17/12/2019
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 410
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

mysqld in MySQL 5.0.x prior to 5.0.88 and 5.1.x prior to 5.1.41 does not (1) properly handle errors during execution of certain SELECT statements with subqueries, and does not (2) preserve certain null_value flags during execution of statements that use the GeomFromWKB function, which allows remote authenticated users to cause a denial of service (daemon crash) via a crafted statement.

Vulnerable Product Search on Vulmon Subscribe to Product

oracle mysql 5.0.25

mysql mysql 5.0.24

oracle mysql 5.0.0

oracle mysql 5.0.11

mysql mysql 5.0.30

oracle mysql 5.0.42

oracle mysql 5.0.32

oracle mysql 5.0.51

oracle mysql 5.0.26

oracle mysql 5.0.33

mysql mysql 5.0.66

oracle mysql 5.0.7

mysql mysql 5.1.23

mysql mysql 5.1.5

oracle mysql 5.1.13

oracle mysql 5.1.14

oracle mysql 5.1.30

oracle mysql 5.1

oracle mysql 5.1.18

oracle mysql 5.1.19

mysql mysql 5.0.2

mysql mysql 5.0.20

mysql mysql 5.0.16

mysql mysql 5.0.0

mysql mysql 5.0.1

mysql mysql 5.0.10

mysql mysql 5.0.56

mysql mysql 5.0.54

oracle mysql 5.0.51a

mysql mysql 5.0.5.0.21

mysql mysql 5.0.5

mysql mysql 5.0.4

oracle mysql 5.0.75

oracle mysql 5.0.77

oracle mysql 5.1.6

oracle mysql 5.1.3

oracle mysql 5.1.11

oracle mysql 5.1.12

oracle mysql 5.1.10

oracle mysql 5.1.1

oracle mysql 5.1.20

oracle mysql 5.0.21

mysql mysql 5.0.17

oracle mysql 5.0.14

mysql mysql 5.0.15

oracle mysql 5.0.30

oracle mysql 5.0.50

oracle mysql 5.0.52

oracle mysql 5.0.6

oracle mysql 5.0.3

oracle mysql 5.0.41

oracle mysql 5.0.8

oracle mysql 5.0.81

oracle mysql 5.1.4

oracle mysql 5.1.9

oracle mysql 5.1.17

oracle mysql 5.1.2

mysql mysql 5.1.32

oracle mysql 5.1.21

oracle mysql 5.0.23

oracle mysql 5.0.22

mysql mysql 5.0.22.1.0.1

oracle mysql 5.0.18

oracle mysql 5.0.19

oracle mysql 5.0.12

oracle mysql 5.0.13

oracle mysql 5.0.45

mysql mysql 5.0.44

oracle mysql 5.0.38

mysql mysql 5.0.36

mysql mysql 5.0.3

oracle mysql 5.0.37

oracle mysql 5.0.27

mysql mysql 5.0.60

mysql mysql 5.0.82

oracle mysql 5.0.83

oracle mysql 5.1.7

oracle mysql 5.1.8

oracle mysql 5.1.15

oracle mysql 5.1.16

oracle mysql 5.1.22

Vendor Advisories

Synopsis Moderate: mysql security update Type/Severity Security Advisory: Moderate Topic Updated mysql packages that fix multiple security issues are now availablefor Red Hat Enterprise Linux 5This update has been rated as having moderate security impact by the RedHat Security Response Team Descr ...
Several vulnerabilities have been discovered in the MySQL database server The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-4019 Domas Mituzas discovered that mysqld does not properly handle errors during execution of certain SELECT statements with subqueries, and does not preserve certain null_value fla ...
It was discovered that MySQL could be made to overwrite existing table files in the data directory An authenticated user could use the DATA DIRECTORY and INDEX DIRECTORY options to possibly bypass privilege checks This update alters table creation behaviour by disallowing the use of the MySQL data directory in DATA DIRECTORY and INDEX DIRECTORY o ...

Exploits

source: wwwsecurityfocuscom/bid/37297/info MySQL is prone to multiple remote denial-of-service vulnerabilities because it fails to handle certain SQL expressions An attacker can exploit these issues to crash the application, denying access to legitimate users Versions prior to MySQL 5088 and 5141 are vulnerable drop table if ...
source: wwwsecurityfocuscom/bid/37297/info MySQL is prone to multiple remote denial-of-service vulnerabilities because it fails to handle certain SQL expressions An attacker can exploit these issues to crash the application, denying access to legitimate users Versions prior to MySQL 5088 and 5141 are vulnerable drop table if ex ...