Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (crash) via (1) IN or (2) CASE operations with NULL arguments that are explicitly specified or indirectly provided by the WITH ROLLUP modifier.
Weaknesses in this category are related to improper management of system resources.
Link | Tags |
---|---|
http://bugs.mysql.com/bug.php?id=54477 | patch exploit |
http://www.ubuntu.com/usn/USN-1397-1 | vendor advisory |
http://www.securityfocus.com/bid/42596 | vdb entry |
http://www.ubuntu.com/usn/USN-1017-1 | vendor advisory |
http://www.mandriva.com/security/advisories?name=MDVSA-2011:012 | vendor advisory |
http://www.redhat.com/support/errata/RHSA-2011-0164.html | vendor advisory |
http://www.vupen.com/english/advisories/2011/0170 | vdb entry vendor advisory |
http://www.vupen.com/english/advisories/2011/0133 | vdb entry vendor advisory |
http://dev.mysql.com/doc/refman/5.1/en/news-5-1-49.html | |
http://www.mandriva.com/security/advisories?name=MDVSA-2010:155 | vendor advisory |
http://secunia.com/advisories/42936 | third party advisory vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=628172 | patch exploit |
http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html | vendor advisory |
http://www.openwall.com/lists/oss-security/2010/09/28/10 | mailing list exploit patch |