CVE-2007-6304Mysql vulnerability

5 documents5 sources
Severity
5.0MEDIUMNVD
EPSS
4.9%
top 10.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 10
Latest updateMay 1

Description

The federated engine in MySQL 5.0.x before 5.0.51a, 5.1.x before 5.1.23, and 6.0.x before 6.0.4, when performing a certain SHOW TABLE STATUS query, allows remote MySQL servers to cause a denial of service (federated handler crash and daemon crash) via a response that lacks the minimum required number of columns.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

NVDmysql/mysql14 versions+13
NVDoracle/mysql32 versions+31

🔴Vulnerability Details

1
GHSA
GHSA-gmq9-53hm-68cj: The federated engine in MySQL 52022-05-01

📋Vendor Advisories

2
Ubuntu
MySQL vulnerabilities2007-12-21
Red Hat
mysql: crash in federated engine caused by remote MySQL server2007-07-19

💬Community

1
Bugzilla
CVE-2007-6304 mysql: crash in federated engine caused by remote MySQL server2007-12-11
CVE-2007-6304 — Mysql vulnerability | cvebase