|
|
|
![]() |
Vulnerability Note VU#516492MySQL fails to validate length of password fieldOverviewA vulnerability in MySQL could permit a malicious user to execute arbitrary code on the system.I. DescriptionMySQL is a database system. MySQL contains a buffer overflow vulnerability in the processing of the password field of the MySQL database, specifically "SET PASSWORD". A malicious user who has the permissions to execute the "ALTER TABLE" command on tables in the "mysql" database may be able to exploit this vulnerability. MySQL3 versions 3.0.57 and earlier and MySQL4 versions 4.0.14 and earlier are reported to be vulnerable.An exploit has been posted publicly
References
Thanks to Jedi/Sector One for reporting this vulnerability. This document was written by Jason A Rafail.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||||||||