CVE-2005-2572Oracle Mysql vulnerability

2 documents2 sources
Severity
8.5HIGHNVD
EPSS
1.4%
top 19.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 16
Latest updateMay 1

Description

MySQL, when running on Windows, allows remote authenticated users with insert privileges on the mysql.func table to cause a denial of service (server hang) and possibly execute arbitrary code via (1) a request for a non-library file, which causes the Windows LoadLibraryEx function to block, or (2) a request for a function in a library that has the XXX_deinit or XXX_init functions defined but is not tailored for mySQL, such as jpeg1x32.dll and jpeg2x32.dll.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 6.8 | Impact: 10.0

Affected Packages1 packages

NVDoracle/mysql5.0.33

🔴Vulnerability Details

1
GHSA
GHSA-654g-56x3-m3r6: MySQL, when running on Windows, allows remote authenticated users with insert privileges on the mysql2022-05-01