SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#516492

MySQL fails to validate length of password field

Overview

A vulnerability in MySQL could permit a malicious user to execute arbitrary code on the system.

I. Description

MySQL is a database system. MySQL contains a buffer overflow vulnerability in the processing of the password field of the MySQL database, specifically "SET PASSWORD". A malicious user who has the permissions to execute the "ALTER TABLE" command on tables in the "mysql" database may be able to exploit this vulnerability. MySQL3 versions 3.0.57 and earlier and MySQL4 versions 4.0.14 and earlier are reported to be vulnerable.

An exploit has been posted publicly

II. Impact

Exploitation of this vulnerability could allow the malicious user to execute arbitrary code with the privileges of the mysqld process, by default user "mysql".

III. Solution

This issue is resolved in MySQL versions 3.23.58 and 4.0.15. Upgrade or apply a patch as recommended by your vendor.

Systems Affected

VendorStatusDate NotifiedDate Updated
DebianVulnerable15-Sep-2003
MySQLVulnerable15-Sep-2003
OpenPKGVulnerable15-Sep-2003

References


http://www.mysql.com/
http://www.secunia.com/advisories/9709/

Credit

Thanks to Jedi/Sector One for reporting this vulnerability.

This document was written by Jason A Rafail.

Other Information

Date Public:2003-09-10
Date First Published:2003-09-15
Date Last Updated:2003-09-15
CERT Advisory: 
CVE-ID(s):CAN-2003-0780
NVD-ID(s):CAN-2003-0780
US-CERT Technical Alerts: 
Metric:1.69
Document Revision:5

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2003 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader