Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2010-3683Mysql vulnerability

9 documents6 sources
Severity
4.0MEDIUMNVD
EPSS
8.0%
top 7.89%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedJan 11
Latest updateMay 13

Description

Oracle MySQL 5.1 before 5.1.49 and 5.5 before 5.5.5 sends an OK packet when a LOAD DATA INFILE request generates SQL errors, which allows remote authenticated users to cause a denial of service (mysqld daemon crash) via a crafted request.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 8.0 | Impact: 2.9

Affected Packages2 packages

NVDoracle/mysql52 versions+51
NVDmysql/mysql6 versions+5

Patches

🔴Vulnerability Details

1
GHSA
GHSA-5q5q-54rm-rj75: Oracle MySQL 52022-05-13

💥Exploits & PoCs

2
Exploit-DB
OraclMySQL 5.1.48 - 'LOAD DATA INFILE' Denial of Service2010-08-20
Exploit-DB
freeFTPd 1.0 - 'Username' Remote Overflow (Metasploit)2010-07-03

📋Vendor Advisories

3
Ubuntu
MySQL vulnerabilities2012-03-12
Ubuntu
MySQL vulnerabilities2010-11-11
Red Hat
MySQL: mysqld DoS (assertion failure) while reading the file back into a table (MySQL bug #52512)2010-07-09

💬Community

2
Bugzilla
CVE-2010-3676 CVE-2010-3677 CVE-2010-3678 CVE-2010-3679 CVE-2010-3680 CVE-2010-3681 CVE-2010-3682 CVE-2010-3683 mysql various flaws [fedora-all]2010-09-23
Bugzilla
CVE-2010-3683 MySQL: mysqld DoS (assertion failure) while reading the file back into a table (MySQL bug #52512)2010-08-30
CVE-2010-3683 — Mysql vulnerability | cvebase