CVE-2010-3833
published 2011-01-14CVE-2010-3833: MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 does not properly propagate type errors, which allows remote attackers to cause a denial of…
PriorityP423medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.05%
86.1th percentile
MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 does not properly propagate type errors, which allows remote attackers to cause a denial of service (server crash) via crafted arguments to extreme-value functions such as (1) LEAST and (2) GREATEST, related to KILL_BAD_DATA and a "CREATE TABLE ... SELECT."
Affected
126 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat5.0MEDIUM
vendor_ubuntu3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-75p5-8637-4fhr: MySQL 5
ghsa_unreviewed·2022-05-13
CVE-2010-3833 [MEDIUM] GHSA-75p5-8637-4fhr: MySQL 5
MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 does not properly propagate type errors, which allows remote attackers to cause a denial of service (server crash) via crafted arguments to extreme-value functions such as (1) LEAST and (2) GREATEST, related to KILL_BAD_DATA and a "CREATE TABLE ... SELECT."
Ubuntu
MySQL vulnerabilities
vendor_ubuntu·2012-03-12
CVE-2007-5925 MySQL vulnerabilities
Title: MySQL vulnerabilities
Summary: Several security issues were fixed in MySQL.
Multiple security issues were discovered in MySQL and this update includes
new upstream MySQL versions to fix these issues.
MySQL has been updated to 5.1.61 in Ubuntu 10.04 LTS, Ubuntu 10.10,
Ubuntu 11.04 and Ubuntu 11.10. Ubuntu 8.04 LTS has been updated to
MySQL 5.0.95.
In addition to security fixes, the updated packages contain bug fixes, new
features, and possibly incompatible changes.
Please see the following for more information:
http://dev.mysql.com/doc/refman/5.1/en/news-5-1-x.html
http://dev.mysql.com/doc/refman/5.0/en/news-5-0-x.html
http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
MySQL vulnerabilities
vendor_ubuntu·2010-11-11·CVSS 3.5
CVE-2010-2008 [LOW] MySQL vulnerabilities
Title: MySQL vulnerabilities
It was discovered that MySQL incorrectly handled certain requests with the
UPGRADE DATA DIRECTORY NAME command. An authenticated user could exploit
this to make MySQL crash, causing a denial of service. This issue only
affected Ubuntu 9.10 and 10.04 LTS. (CVE-2010-2008)
It was discovered that MySQL incorrectly handled joins involving a table
with a unique SET column. An authenticated user could exploit this to make
MySQL crash, causing a denial of service. This issue only affected Ubuntu
6.06 LTS, 8.04 LTS, 9.10 and 10.04 LTS. (CVE-2010-3677)
It was discovered that MySQL incorrectly handled NULL arguments to IN() or
CASE operations. An authenticated user could exploit this to make MySQL
crash, causing a denial of service. This issue only affected Ubuntu 9.10
Red Hat
MySQL: CREATE TABLE ... SELECT causes crash when KILL_BAD_DATA is returned (MySQL Bug#55826)
vendor_redhat·2010-08-08·CVSS 5.0
CVE-2010-3833 [MEDIUM] MySQL: CREATE TABLE ... SELECT causes crash when KILL_BAD_DATA is returned (MySQL Bug#55826)
MySQL: CREATE TABLE ... SELECT causes crash when KILL_BAD_DATA is returned (MySQL Bug#55826)
MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 does not properly propagate type errors, which allows remote attackers to cause a denial of service (server crash) via crafted arguments to extreme-value functions such as (1) LEAST and (2) GREATEST, related to KILL_BAD_DATA and a "CREATE TABLE ... SELECT."
Package: mysql (Red Hat Enterprise Linux 4) - Not affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-3833 CVE-2010-3835 CVE-2010-3836 CVE-2010-3837 CVE-2010-3838 CVE-2010-3839 CVE-2010-3840 mysql various flaws [fedora-12]
bugzilla·2010-10-22·CVSS 5.0
CVE-2010-3833 [MEDIUM] CVE-2010-3833 CVE-2010-3835 CVE-2010-3836 CVE-2010-3837 CVE-2010-3838 CVE-2010-3839 CVE-2010-3840 mysql various flaws [fedora-12]
CVE-2010-3833 CVE-2010-3835 CVE-2010-3836 CVE-2010-3837 CVE-2010-3838 CVE-2010-3839 CVE-2010-3840 mysql various flaws [fedora-12]
fedora-12 tracking bug for mysql: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
Adding parent bug CVE-2010-3835
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=640751,640819
---
Adding parent bug CVE-2010-3836
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=640751,640819,640845
---
Adding parent bug CVE-2010-3837, CVE-2010-3838, CVE-2010-3839,
CVE-2010-3840
New bodhi update url:
https://admin.fedoraproj
Bugzilla
CVE-2010-3833 CVE-2010-3835 CVE-2010-3836 CVE-2010-3839 CVE-2010-3840 mysql various flaws [fedora-13]
bugzilla·2010-10-22·CVSS 5.0
CVE-2010-3833 [MEDIUM] CVE-2010-3833 CVE-2010-3835 CVE-2010-3836 CVE-2010-3839 CVE-2010-3840 mysql various flaws [fedora-13]
CVE-2010-3833 CVE-2010-3835 CVE-2010-3836 CVE-2010-3839 CVE-2010-3840 mysql various flaws [fedora-13]
fedora-13 tracking bug for mysql: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
Adding parent bug CVE-2010-3835
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=640751,640819
---
Adding parent bug CVE-2010-3836
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=640751,640819,640845
---
Adding parent bug CVE-2010-3839
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=640751,640819,640845,640861
---
Bugzilla
CVE-2010-3833 MySQL: CREATE TABLE ... SELECT causes crash when KILL_BAD_DATA is returned (MySQL Bug#55826)
bugzilla·2010-10-06·CVSS 5.0
CVE-2010-3833 [MEDIUM] CVE-2010-3833 MySQL: CREATE TABLE ... SELECT causes crash when KILL_BAD_DATA is returned (MySQL Bug#55826)
CVE-2010-3833 MySQL: CREATE TABLE ... SELECT causes crash when KILL_BAD_DATA is returned (MySQL Bug#55826)
A flaw in MySQL versions prior to 5.1.51 [1] was reported [2] that could allow an authenticated user to kill connections to MySQL. During evaluation of arguments to extreme-value functions (such as LEAST() and GREATEST()), type errors did not propagate properly, causing the server to crash, and any other connections to the server to be terminated.
[1] http://dev.mysql.com/doc/refman/5.1/en/news-5-1-51.html
[2] http://bugs.mysql.com/bug.php?id=55826
Discussion:
This issue has been assigned the name CVE-2010-3833:
http://article.gmane.org/gmane.comp.security.oss.general/3627
---
Created attachment 453399
upstream patch
---
This issue did NOT affect the versions of the mysql pac
http://bugs.mysql.com/bug.php?id=55826http://dev.mysql.com/doc/refman/5.0/en/news-5-0-92.htmlhttp://dev.mysql.com/doc/refman/5.1/en/news-5-1-51.htmlhttp://dev.mysql.com/doc/refman/5.5/en/news-5-5-6.htmlhttp://lists.apple.com/archives/security-announce/2011//Jun/msg00000.htmlhttp://secunia.com/advisories/42875http://secunia.com/advisories/42936http://support.apple.com/kb/HT4723http://www.debian.org/security/2011/dsa-2143http://www.mandriva.com/security/advisories?name=MDVSA-2010:222http://www.mandriva.com/security/advisories?name=MDVSA-2010:223http://www.redhat.com/support/errata/RHSA-2010-0825.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0164.htmlhttp://www.securityfocus.com/bid/43676http://www.turbolinux.co.jp/security/2011/TLSA-2011-3j.txthttp://www.ubuntu.com/usn/USN-1017-1http://www.ubuntu.com/usn/USN-1397-1http://www.vupen.com/english/advisories/2011/0105http://www.vupen.com/english/advisories/2011/0170http://www.vupen.com/english/advisories/2011/0345https://bugzilla.redhat.com/show_bug.cgi?id=640751https://exchange.xforce.ibmcloud.com/vulnerabilities/64845http://bugs.mysql.com/bug.php?id=55826http://dev.mysql.com/doc/refman/5.0/en/news-5-0-92.htmlhttp://dev.mysql.com/doc/refman/5.1/en/news-5-1-51.htmlhttp://dev.mysql.com/doc/refman/5.5/en/news-5-5-6.htmlhttp://lists.apple.com/archives/security-announce/2011//Jun/msg00000.htmlhttp://secunia.com/advisories/42875http://secunia.com/advisories/42936http://support.apple.com/kb/HT4723http://www.debian.org/security/2011/dsa-2143http://www.mandriva.com/security/advisories?name=MDVSA-2010:222http://www.mandriva.com/security/advisories?name=MDVSA-2010:223http://www.redhat.com/support/errata/RHSA-2010-0825.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0164.htmlhttp://www.securityfocus.com/bid/43676http://www.turbolinux.co.jp/security/2011/TLSA-2011-3j.txthttp://www.ubuntu.com/usn/USN-1017-1http://www.ubuntu.com/usn/USN-1397-1http://www.vupen.com/english/advisories/2011/0105http://www.vupen.com/english/advisories/2011/0170http://www.vupen.com/english/advisories/2011/0345https://bugzilla.redhat.com/show_bug.cgi?id=640751https://exchange.xforce.ibmcloud.com/vulnerabilities/64845
2011-01-14
Published