Back to search
CVE-2009-4019
Published: Nov 30, 2009
Modified: Aug 7, 2024
PUBLISHED
Description
mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of certain SELECT statements with subqueries, and does not (2) preserve certain null_value flags during execution of statements that use the GeomFromWKB function, which allows remote authenticated users to cause a denial of service (daemon crash) via a crafted statement.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
38573
third-party-advisory
x_refsource_SECUNIA
http://bugs.mysql.com/48291
x_refsource_CONFIRM
USN-1397-1
vendor-advisory
x_refsource_UBUNTU
[oss-security] 20091123 Re: CVE Request - MySQL - 5.0.88
mailing-list
x_refsource_MLIST
38517
third-party-advisory
x_refsource_SECUNIA
RHSA-2010:0109
vendor-advisory
x_refsource_REDHAT
ADV-2010-1107
vdb-entry
x_refsource_VUPEN
FEDORA-2009-12180
vendor-advisory
x_refsource_FEDORA
USN-897-1
vendor-advisory
x_refsource_UBUNTU
SUSE-SR:2010:011
vendor-advisory
x_refsource_SUSE
APPLE-SA-2010-03-29-1
vendor-advisory
x_refsource_APPLE
https://bugzilla.redhat.com/show_bug.cgi?id=540906
x_refsource_CONFIRM
http://dev.mysql.com/doc/refman/5.1/en/news-5-1-41.html
x_refsource_CONFIRM
http://dev.mysql.com/doc/refman/5.0/en/news-5-0-88.html
x_refsource_CONFIRM
oval:org.mitre.oval:def:11349
vdb-entry
signature
x_refsource_OVAL
http://support.apple.com/kb/HT4077
x_refsource_CONFIRM
[oss-security] 20091121 CVE Request - MySQL - 5.0.88
mailing-list
x_refsource_MLIST
37717
third-party-advisory
x_refsource_SECUNIA
[oss-security] 20091121 Re: CVE Request - MySQL - 5.0.88
mailing-list
x_refsource_MLIST
http://bugs.mysql.com/47780
x_refsource_CONFIRM
oval:org.mitre.oval:def:8500
vdb-entry
signature
x_refsource_OVAL
DSA-1997
vendor-advisory
x_refsource_DEBIAN
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now