Resource management error in mysql - CVE-2010-3679

 

Resource management error in mysql - CVE-2010-3679

Published: January 11, 2011 / Updated: August 11, 2020


Vulnerability identifier: #VU45465
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2010-3679
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote #AU# to perform service disruption.

Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (mysqld daemon crash) via certain arguments to the BINLOG command, which triggers an access of uninitialized memory, as demonstrated by valgrind.


Affected software

mysql

How to mitigate CVE-2010-3679

Install update from vendor's website.


Links to Public Exploits and PoC-codes

External References

Related Security Bulletins