The in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40, and 5.1 before 5.1.18-beta, allows context-dependent attackers to cause a denial of service (crash) via a crafted IF clause that results in a divide-by-zero error and a NULL pointer dereference.
CPE | Name | Operator | Version |
---|---|---|---|
ubuntu_linux | eq | 6.06 | |
ubuntu_linux | eq | 7.04 | |
ubuntu_linux | eq | 6.10 | |
debian_linux | eq | 3.1 | |
debian_linux | eq | 4.0 | |
mysql | ge | 5.1 | |
mysql | le | 5.1.17 | |
mysql | lt | 5.0.40 |
bugs.mysql.com/bug.php?id=27513
lists.mysql.com/commits/23685
lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.html
packetstormsecurity.com/files/124295/MySQL-5.0.x-Denial-Of-Service.html
secunia.com/advisories/25188
secunia.com/advisories/25196
secunia.com/advisories/25255
secunia.com/advisories/25389
secunia.com/advisories/25946
secunia.com/advisories/27155
secunia.com/advisories/27823
secunia.com/advisories/28838
secunia.com/advisories/30351
security.gentoo.org/glsa/glsa-200705-11.xml
www.debian.org/security/2007/dsa-1413
www.mandriva.com/security/advisories?name=MDKSA-2007:139
www.osvdb.org/34734
www.redhat.com/support/errata/RHSA-2008-0364.html
www.securityfocus.com/bid/23911
www.trustix.org/errata/2007/0017/
www.vupen.com/english/advisories/2007/1731
exchange.xforce.ibmcloud.com/vulnerabilities/34232
issues.rpath.com/browse/RPL-1356
oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9930
usn.ubuntu.com/528-1/
www.exploit-db.com/exploits/30020