CVE-2002-0969Classic Buffer Overflow in Oracle Mysql

Severity
7.8HIGHNVD
EPSS
0.1%
top 71.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 11
Latest updateApr 30

Description

Buffer overflow in MySQL daemon (mysqld) before 3.23.50, and 4.0 beta before 4.02, on the Win32 platform, allows local users to execute arbitrary code via a long "datadir" parameter in the my.ini initialization file, whose permissions on Windows allow Full Control to the Everyone group.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages1 packages

NVDoracle/mysql4.0.04.0.2+1

Patches

🔴Vulnerability Details

1
GHSA
GHSA-p742-xf6g-v4h3: Buffer overflow in MySQL daemon (mysqld) before 32022-04-30

📐Framework References

1
CWE
Incorrect Permission Assignment for Critical Resource