Free and open-source vulnerability scanner
Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.
Install NowAvailable for macOS, Windows, and Linux

MySQL 'sql_parse.cc' Multiple Format String Vulnerabilities
Information
Severity
Severity
High
Family
Family
Denial of Service
CVSSv2 Base
CVSSv2 Base
8.5
CVSSv2 Vector
CVSSv2 Vector
AV:N/AC:M/Au:S/C:C/I:C/A:C
Solution Type
Solution Type
Vendor Patch
Created
Created
13 years ago
Modified
Modified
4 years ago
Summary
The host is running MySQL and is prone to Multiple Format String vulnerabilities.
Insight
Insight
The flaws are due to error in the 'dispatch_command' function in sql_parse.cc in libmysqld/ which can caused via format string specifiers in a database name in a 'COM_CREATE_DB' or 'COM_DROP_DB' request.
Affected Software
Affected Software
MySQL version 4.0.0 to 5.0.83 on all running platform.
Solution
Solution
Upgrade to MySQL version 5.1.36 or later.