CVE-2004-0837
published 2004-11-03CVE-2004-0837: MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows attackers to cause a denial of service (crash or hang) via multiple threads that simultaneously alter…
PriorityP413low2.6CVSS 2.0
AVNACHAuNCNINAP
EPSS
4.90%
91.1th percentile
MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows attackers to cause a denial of service (crash or hang) via multiple threads that simultaneously alter MERGE table UNIONs.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| mysql | mysql | — | — |
| oracle | mysql | >= 3.20 < 3.23.49 | 3.23.49 |
| oracle | mysql | >= 4.0.0 < 4.0.21 | 4.0.21 |
CVSS provenance
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:N/I:N/A:P
vendor_redhat2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
mysql vulnerabilities
vendor_ubuntu·2004-11-25
CVE-2004-0837 mysql vulnerabilities
Title: mysql vulnerabilities
Summary: mysql vulnerabilities
Several vulnerabilities have been discovered in the MySQL database
server.
Lukasz Wojtow discovered a potential buffer overflow in the function
mysql_real_connect(). A malicious name server could send specially
crafted DNS packages which might result in execution of arbitrary code
with the database server's privileges. However, it is believed that
this bug cannot be exploited with the C Standard library (glibc) that
Ubuntu uses. (CAN-2004-0836).
Dean Ellis noticed a flaw that allows an authorized MySQL user to
cause a denial of service (crash or hang) via concurrent execution of
certain statements (ALTER TABLE ... UNION=, FLUSH TABLES) on tables of
type MERGE (CAN-2004-0837)
Some query strings containing a double quote (like
Red Hat
security flaw
vendor_redhat·2004-01-15·CVSS 2.6
CVE-2004-0837 [LOW] security flaw
security flaw
MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows attackers to cause a denial of service (crash or hang) via multiple threads that simultaneously alter MERGE table UNIONs.
GHSA
GHSA-8p34-xxjh-4hrg: MySQL 4
ghsa_unreviewed·2022-04-29
CVE-2004-0837 [LOW] GHSA-8p34-xxjh-4hrg: MySQL 4
MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows attackers to cause a denial of service (crash or hang) via multiple threads that simultaneously alter MERGE table UNIONs.
No detection rules found.
No public exploits indexed.
http://bugs.mysql.com/2408http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000892http://lists.mysql.com/internals/16168http://lists.mysql.com/internals/16173http://lists.mysql.com/internals/16174http://marc.info/?l=bugtraq&m=110140517515735&w=2http://mysql.bkbits.net:8080/mysql-3.23/diffs/myisammrg/myrg_open.c%401.15http://secunia.com/advisories/12783/http://securitytracker.com/id?1011606http://sunsolve.sun.com/search/document.do?assetkey=1-26-101864-1http://www.ciac.org/ciac/bulletins/p-018.shtmlhttp://www.debian.org/security/2004/dsa-562http://www.gentoo.org/security/en/glsa/glsa-200410-22.xmlhttp://www.redhat.com/support/errata/RHSA-2004-597.htmlhttp://www.redhat.com/support/errata/RHSA-2004-611.htmlhttp://www.securityfocus.com/bid/11357http://www.trustix.org/errata/2004/0054/https://exchange.xforce.ibmcloud.com/vulnerabilities/17667http://bugs.mysql.com/2408http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000892http://lists.mysql.com/internals/16168http://lists.mysql.com/internals/16173http://lists.mysql.com/internals/16174http://marc.info/?l=bugtraq&m=110140517515735&w=2http://mysql.bkbits.net:8080/mysql-3.23/diffs/myisammrg/myrg_open.c%401.15http://secunia.com/advisories/12783/http://securitytracker.com/id?1011606http://sunsolve.sun.com/search/document.do?assetkey=1-26-101864-1http://www.ciac.org/ciac/bulletins/p-018.shtmlhttp://www.debian.org/security/2004/dsa-562http://www.gentoo.org/security/en/glsa/glsa-200410-22.xmlhttp://www.redhat.com/support/errata/RHSA-2004-597.htmlhttp://www.redhat.com/support/errata/RHSA-2004-611.htmlhttp://www.securityfocus.com/bid/11357http://www.trustix.org/errata/2004/0054/https://exchange.xforce.ibmcloud.com/vulnerabilities/17667
2004-11-03
Published