Lucene search

K
ubuntuUbuntuUSN-440-1
HistoryMar 22, 2007 - 12:00 a.m.

MySQL vulnerability

2007-03-2200:00:00
ubuntu.com
45

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.1

Confidence

Low

EPSS

0.001

Percentile

35.8%

Releases

  • Ubuntu 6.10
  • Ubuntu 6.06

Details

Stefan Streichbier and B. Mueller of SEC Consult discovered that MySQL
subselect queries using “ORDER BY” could be made to crash the MySQL
server. An attacker with access to a MySQL instance could cause an
intermitant denial of service.

OSVersionArchitecturePackageVersionFilename
Ubuntu6.10noarchmysql-server-5.0< 5.0.24a-9ubuntu0.1UNKNOWN
Ubuntu6.06noarchmysql-server-5.0< 5.0.22-0ubuntu6.06.3UNKNOWN

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.1

Confidence

Low

EPSS

0.001

Percentile

35.8%