MySQL 4.1.9, and possibly earlier versions, allows remote attackers with certain privileges to cause a denial of service (application crash) via a use command followed by an MS-DOS device name such as (1) LPT1 or (2) PRN.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=111091250923281&w=2 | mailing list |
http://bugs.mysql.com/bug.php?id=9148 | exploit vendor advisory |
http://secunia.com/advisories/14564 | third party advisory vendor advisory |