CVE-2007-6304
published 2007-12-10CVE-2007-6304: The federated engine in MySQL 5.0.x before 5.0.51a, 5.1.x before 5.1.23, and 6.0.x before 6.0.4, when performing a certain SHOW TABLE STATUS query, allows…
PriorityP419medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.96%
85.7th percentile
The federated engine in MySQL 5.0.x before 5.0.51a, 5.1.x before 5.1.23, and 6.0.x before 6.0.4, when performing a certain SHOW TABLE STATUS query, allows remote MySQL servers to cause a denial of service (federated handler crash and daemon crash) via a response that lacks the minimum required number of columns.
Affected
46 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat5.0MEDIUM
vendor_ubuntu4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gmq9-53hm-68cj: The federated engine in MySQL 5
ghsa_unreviewed·2022-05-01
CVE-2007-6304 [MEDIUM] GHSA-gmq9-53hm-68cj: The federated engine in MySQL 5
The federated engine in MySQL 5.0.x before 5.0.51a, 5.1.x before 5.1.23, and 6.0.x before 6.0.4, when performing a certain SHOW TABLE STATUS query, allows remote MySQL servers to cause a denial of service (federated handler crash and daemon crash) via a response that lacks the minimum required number of columns.
Ubuntu
MySQL vulnerabilities
vendor_ubuntu·2007-12-21·CVSS 4.0
CVE-2007-3781 [MEDIUM] MySQL vulnerabilities
Title: MySQL vulnerabilities
Summary: MySQL vulnerabilities
Joe Gallo and Artem Russakovskii discovered that the InnoDB
engine in MySQL did not properly perform input validation. An
authenticated user could use a crafted CONTAINS statement to
cause a denial of service. (CVE-2007-5925)
It was discovered that under certain conditions MySQL could be
made to overwrite system table information. An authenticated
user could use a crafted RENAME statement to escalate privileges.
(CVE-2007-5969)
Philip Stoev discovered that the the federated engine of MySQL
did not properly handle responses with a small number of columns.
An authenticated user could use a crafted response to a SHOW
TABLE STATUS query and cause a denial of service. (CVE-2007-6304)
It was discovered that MySQL did not properly e
Red Hat
mysql: crash in federated engine caused by remote MySQL server
vendor_redhat·2007-07-19·CVSS 5.0
CVE-2007-6304 [MEDIUM] mysql: crash in federated engine caused by remote MySQL server
mysql: crash in federated engine caused by remote MySQL server
The federated engine in MySQL 5.0.x before 5.0.51a, 5.1.x before 5.1.23, and 6.0.x before 6.0.4, when performing a certain SHOW TABLE STATUS query, allows remote MySQL servers to cause a denial of service (federated handler crash and daemon crash) via a response that lacks the minimum required number of columns.
Statement: Not vulnerable. The MySQL versions as shipped in Red Hat Enterprise Linux 2.1, 3, and 4 do not support federated storage engine. The MySQL package as shipped in Red Hat Enterprise Linux 5, Red Hat Application Stack v1, and Red Hat Application Stack v2 are not compiled with support for federated storage engine.
No detection rules found.
No public exploits indexed.
http://bugs.mysql.com/bug.php?id=29801http://dev.mysql.com/doc/refman/5.0/en/releasenotes-es-5-0-52.htmlhttp://dev.mysql.com/doc/refman/5.1/en/news-5-1-23.htmlhttp://dev.mysql.com/doc/refman/6.0/en/news-6-0-4.htmlhttp://lists.mysql.com/announce/502http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.htmlhttp://osvdb.org/42609http://secunia.com/advisories/28063http://secunia.com/advisories/28128http://secunia.com/advisories/28343http://secunia.com/advisories/28637http://secunia.com/advisories/28739http://secunia.com/advisories/28838http://secunia.com/advisories/29706http://security.gentoo.org/glsa/glsa-200804-04.xmlhttp://securitytracker.com/id?1019085http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0040http://www.debian.org/security/2008/dsa-1451http://www.mandriva.com/security/advisories?name=MDVSA-2008:017http://www.mandriva.com/security/advisories?name=MDVSA-2008:028http://www.securityfocus.com/archive/1/487606/100/0/threadedhttp://www.securityfocus.com/bid/26832http://www.vupen.com/english/advisories/2007/4198https://exchange.xforce.ibmcloud.com/vulnerabilities/38990https://issues.rpath.com/browse/RPL-2187https://usn.ubuntu.com/559-1/http://bugs.mysql.com/bug.php?id=29801http://dev.mysql.com/doc/refman/5.0/en/releasenotes-es-5-0-52.htmlhttp://dev.mysql.com/doc/refman/5.1/en/news-5-1-23.htmlhttp://dev.mysql.com/doc/refman/6.0/en/news-6-0-4.htmlhttp://lists.mysql.com/announce/502http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.htmlhttp://osvdb.org/42609http://secunia.com/advisories/28063http://secunia.com/advisories/28128http://secunia.com/advisories/28343http://secunia.com/advisories/28637http://secunia.com/advisories/28739http://secunia.com/advisories/28838http://secunia.com/advisories/29706http://security.gentoo.org/glsa/glsa-200804-04.xmlhttp://securitytracker.com/id?1019085http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0040http://www.debian.org/security/2008/dsa-1451http://www.mandriva.com/security/advisories?name=MDVSA-2008:017http://www.mandriva.com/security/advisories?name=MDVSA-2008:028http://www.securityfocus.com/archive/1/487606/100/0/threadedhttp://www.securityfocus.com/bid/26832http://www.vupen.com/english/advisories/2007/4198https://exchange.xforce.ibmcloud.com/vulnerabilities/38990https://issues.rpath.com/browse/RPL-2187https://usn.ubuntu.com/559-1/
2007-12-10
Published