Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2005-2558

Overview

Vulnerability Score 4.6 4.6
CVE Id CVE-2005-2558
Last Modified 07 Mar 2011 09:24:41
Published 16 Aug 2005 12:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector LOCAL
Access Complexity LOW
Authentication NONE

CVE-2005-2558

Summary

Stack-based buffer overflow in the init_syms function in MySQL 4.0 before 4.0.25, 4.1 before 4.1.13, and 5.0 before 5.0.7-beta allows remote authenticated users who can create user-defined functions to execute arbitrary code via a long function_name field.

Vulnerable Systems

Application

  • Mysql 4.0.0

  • Mysql 4.0.1

  • Mysql 4.0.10

  • Mysql 4.0.11

  • Mysql 4.0.12

  • Mysql 4.0.13

  • Mysql 4.0.14

  • Mysql 4.0.15

  • Mysql 4.0.18

  • Mysql 4.0.2

  • Mysql 4.0.20

  • Mysql 4.0.21

  • Mysql 4.0.24

  • Mysql 4.0.3

  • Mysql 4.0.4

  • Mysql 4.0.5

  • Mysql 4.0.5a

  • Mysql 4.0.6

  • Mysql 4.0.7

  • Mysql 4.0.8

  • Mysql 4.0.9

  • Mysql 4.1.0

  • Mysql 4.1.0.0

  • Mysql 4.1.10a

  • Mysql 4.1.2

  • Mysql 4.1.3

  • Mysql 4.1.4

  • Mysql 4.1.5

  • Mysql 5.0.0

  • Mysql 5.0.0.0

  • Mysql 5.0.1

  • Mysql 5.0.2

  • Mysql 5.0.3

  • Mysql 5.0.4


References

BID - 14509

MISC - http://www.appsecinc.com/resources/alerts/mysql/2005-002.html

BUGTRAQ - 20050808 [AppSecInc Advisory MYSQL05-V0002] Buffer Overflow in MySQL User Defined Functions

XF - mysql-user-defined-function-bo(21737)

VUPEN - ADV-2008-1326

UBUNTU - USN-180-1

UBUNTU - USN-180-2

FEDORA - FLSA-2006:167803

MANDRIVA - MDKSA-2005:163

DEBIAN - DSA-833

DEBIAN - DSA-831

DEBIAN - DSA-829

SUSE - SUSE-SR:2005:021

SUNALERT - 236703

SECUNIA - 29847

SECUNIA - 20381

SECUNIA - 17027

SCO - SCOSA-2006.18


Last Updated: 27 May 2016 10:40:34