Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2009-5026

Overview

Vulnerability Score 6.8 6.8
CVE Id CVE-2009-5026
Last Modified 29 Oct 2012 11:37:06
Published 16 Aug 2012 08:55:01
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2009-5026

Summary

The executable comment feature in MySQL 5.0.x before 5.0.93 and 5.1.x before 5.1.50, when running in certain slave configurations in which the slave is running a newer version than the master, allows remote attackers to execute arbitrary SQL commands via custom comments.

Vulnerable Systems

Application

  • Mysql 5.0

  • Mysql 5.0.0

  • Mysql 5.0.0.0

  • Mysql 5.0.1

  • Mysql 5.0.10

  • Mysql 5.0.10a

  • Mysql 5.0.11

  • Mysql 5.0.12

  • Mysql 5.0.13

  • Mysql 5.0.14

  • Mysql 5.0.15

  • Mysql 5.0.15a

  • Mysql 5.0.16

  • Mysql 5.0.16a

  • Mysql 5.0.17

  • Mysql 5.0.17a

  • Mysql 5.0.18

  • Mysql 5.0.19

  • Mysql 5.0.1a

  • Mysql 5.0.2

  • Mysql 5.0.20

  • Mysql 5.0.20a

  • Mysql 5.0.21

  • Mysql 5.0.22

  • Mysql 5.0.23

  • Mysql 5.0.24

  • Mysql 5.0.24a

  • Mysql 5.0.27

  • Mysql 5.0.3

  • Mysql 5.0.33

  • Mysql 5.0.37

  • Mysql 5.0.3a

  • Mysql 5.0.4

  • Mysql 5.0.41

  • Mysql 5.0.45

  • Mysql 5.0.4a

  • Mysql 5.0.5

  • Mysql 5.0.51a

  • Mysql 5.0.51b

  • Mysql 5.0.6

  • Mysql 5.0.67

  • Mysql 5.0.7

  • Mysql 5.0.75

  • Mysql 5.0.77

  • Mysql 5.0.8

  • Mysql 5.0.81

  • Mysql 5.0.82

  • Mysql 5.0.83

  • Mysql 5.0.84

  • Mysql 5.0.85

  • Mysql 5.0.86

  • Mysql 5.0.87

  • Mysql 5.0.88

  • Mysql 5.0.89

  • Mysql 5.0.9

  • Mysql 5.0.90

  • Mysql 5.0.91

  • Mysql 5.0.92

  • Mysql 5.1

  • Mysql 5.1.1

  • Mysql 5.1.10

  • Mysql 5.1.11

  • Mysql 5.1.12

  • Mysql 5.1.13

  • Mysql 5.1.14

  • Mysql 5.1.15

  • Mysql 5.1.16

  • Mysql 5.1.17

  • Mysql 5.1.18

  • Mysql 5.1.19

  • Mysql 5.1.2

  • Mysql 5.1.20

  • Mysql 5.1.21

  • Mysql 5.1.22

  • Mysql 5.1.23

  • Mysql 5.1.23 Bk

  • Mysql 5.1.23a

  • Mysql 5.1.24

  • Mysql 5.1.25

  • Mysql 5.1.26

  • Mysql 5.1.27

  • Mysql 5.1.28

  • Mysql 5.1.29

  • Mysql 5.1.3

  • Mysql 5.1.30

  • Mysql 5.1.31

  • Mysql 5.1.32

  • Mysql 5.1.32-bzr

  • Mysql 5.1.33

  • Mysql 5.1.34

  • Mysql 5.1.35

  • Mysql 5.1.36

  • Mysql 5.1.37

  • Mysql 5.1.38

  • Mysql 5.1.39

  • Mysql 5.1.4

  • Mysql 5.1.40

  • Mysql 5.1.41

  • Mysql 5.1.42

  • Mysql 5.1.43

  • Mysql 5.1.44

  • Mysql 5.1.45

  • Mysql 5.1.46

  • Mysql 5.1.47

  • Mysql 5.1.48

  • Mysql 5.1.49


References

CONFIRM - https://bugzilla.redhat.com/show_bug.cgi?id=640177

MLIST - [oss-security] 20111018 Re: MySQL executable comment execution on MySQL slave server (from 2009)

CONFIRM - http://dev.mysql.com/doc/refman/5.1/en/news-5-1-50.html

CONFIRM - http://dev.mysql.com/doc/refman/5.0/en/news-5-0-93.html

CONFIRM - http://bugs.mysql.com/bug.php?id=49124

SUSE - SUSE-SU-2012:0984

SECUNIA - 49179

Related Patches

Novell SUSE 2012:6613 libmysqlclient-devel security update for SLE 11 SP1 i586

Novell SUSE 2012:6613 libmysqlclient-devel security update for SLE 11 SP1 x86_64


Last Updated: 27 May 2016 10:49:40