Resource management error in mysql - CVE-2010-3678

 

Resource management error in mysql - CVE-2010-3678

Published: January 11, 2011 / Updated: August 11, 2020


Vulnerability identifier: #VU45464
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2010-3678
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote #AU# to perform service disruption.

Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (crash) via (1) IN or (2) CASE operations with NULL arguments that are explicitly specified or indirectly provided by the WITH ROLLUP modifier.


Affected software

mysql

How to mitigate CVE-2010-3678

Install update from vendor's website.


Links to Public Exploits and PoC-codes

External References

Related Security Bulletins