CVE-2010-3834
published 2011-01-14CVE-2010-3834: Unspecified vulnerability in MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 allows remote authenticated users to cause a denial of service…
PriorityP413medium4CVSS 2.0
AVNACLAuSCNINAP
EPSS
2.21%
80.6th percentile
Unspecified vulnerability in MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 allows remote authenticated users to cause a denial of service (server crash) via vectors related to "materializing a derived table that required a temporary table for grouping" and "user variable assignments."
Affected
126 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
vendor_redhat4.0MEDIUM
vendor_ubuntu3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
MySQL vulnerabilities
vendor_ubuntu·2012-03-12
CVE-2007-5925 MySQL vulnerabilities
Title: MySQL vulnerabilities
Summary: Several security issues were fixed in MySQL.
Multiple security issues were discovered in MySQL and this update includes
new upstream MySQL versions to fix these issues.
MySQL has been updated to 5.1.61 in Ubuntu 10.04 LTS, Ubuntu 10.10,
Ubuntu 11.04 and Ubuntu 11.10. Ubuntu 8.04 LTS has been updated to
MySQL 5.0.95.
In addition to security fixes, the updated packages contain bug fixes, new
features, and possibly incompatible changes.
Please see the following for more information:
http://dev.mysql.com/doc/refman/5.1/en/news-5-1-x.html
http://dev.mysql.com/doc/refman/5.0/en/news-5-0-x.html
http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
MySQL vulnerabilities
vendor_ubuntu·2010-11-11·CVSS 3.5
CVE-2010-2008 [LOW] MySQL vulnerabilities
Title: MySQL vulnerabilities
It was discovered that MySQL incorrectly handled certain requests with the
UPGRADE DATA DIRECTORY NAME command. An authenticated user could exploit
this to make MySQL crash, causing a denial of service. This issue only
affected Ubuntu 9.10 and 10.04 LTS. (CVE-2010-2008)
It was discovered that MySQL incorrectly handled joins involving a table
with a unique SET column. An authenticated user could exploit this to make
MySQL crash, causing a denial of service. This issue only affected Ubuntu
6.06 LTS, 8.04 LTS, 9.10 and 10.04 LTS. (CVE-2010-3677)
It was discovered that MySQL incorrectly handled NULL arguments to IN() or
CASE operations. An authenticated user could exploit this to make MySQL
crash, causing a denial of service. This issue only affected Ubuntu 9.10
Red Hat
MySQL: user variable assignments crash server when used within query (MySQL Bug#55568)
vendor_redhat·2010-09-28·CVSS 4.0
CVE-2010-3834 [MEDIUM] MySQL: user variable assignments crash server when used within query (MySQL Bug#55568)
MySQL: user variable assignments crash server when used within query (MySQL Bug#55568)
Unspecified vulnerability in MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 allows remote authenticated users to cause a denial of service (server crash) via vectors related to "materializing a derived table that required a temporary table for grouping" and "user variable assignments."
Statement: Not vulnerable. This issue did not affect the versions of mysql as shipped with Red Hat Enterprise Linux 3, 4, 5, or 6.
Package: mysql (Red Hat Enterprise Linux 6) - Not affected
GHSA
GHSA-m2w3-ww5p-6g7f: Unspecified vulnerability in MySQL 5
ghsa_unreviewed·2022-05-13
CVE-2010-3834 [MEDIUM] GHSA-m2w3-ww5p-6g7f: Unspecified vulnerability in MySQL 5
Unspecified vulnerability in MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 allows remote authenticated users to cause a denial of service (server crash) via vectors related to "materializing a derived table that required a temporary table for grouping" and "user variable assignments."
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-3834 MySQL: user variable assignments crash server when used within query (MySQL Bug#55568)
bugzilla·2010-10-06·CVSS 4.0
CVE-2010-3834 [MEDIUM] CVE-2010-3834 MySQL: user variable assignments crash server when used within query (MySQL Bug#55568)
CVE-2010-3834 MySQL: user variable assignments crash server when used within query (MySQL Bug#55568)
A flaw in MySQL versions prior to 5.1.51 [1] was reported [2] that could allow an authenticated user to kill connections to MySQL, where the server could crash after materializing a derived table that required a temporary table for grouping.
[1] http://dev.mysql.com/doc/refman/5.1/en/news-5-1-51.html
[2] http://bugs.mysql.com/bug.php?id=55568
Discussion:
This issue has been assigned the name CVE-2010-3834:
http://article.gmane.org/gmane.comp.security.oss.general/3627
---
Created attachment 453410
upstream patch
---
This issue did NOT affect the versions of mysql as shipped with Fedora 12 and Fedora 13.
---
Statement:
Not vulnerable. This issue did not affect the versions of mysq
Bugzilla
CVE-2009-1189 dbus: invalid fix for CVE-2008-3834
bugzilla·2009-04-20·CVSS 2.1
CVE-2009-1189 [LOW] CVE-2009-1189 dbus: invalid fix for CVE-2008-3834
CVE-2009-1189 dbus: invalid fix for CVE-2008-3834
It was found that the patch to fix CVE-2008-3834 in dbus was incorrect and as a
result the flaw was never properly fixed (remote denial of service
vulnerability). This issue has been assigned CVE-2009-1189.
The upstream bug report is here:
https://bugs.freedesktop.org/show_bug.cgi?id=17803
Our bug report for CVE-2008-3834 is bug #464674 .
Discussion:
The upstream fix is here:
https://bugs.freedesktop.org/attachment.cgi?id=24436
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2010:0018 https://rhn.redhat.com/errata/RHSA-2010-0018.html
http://bugs.mysql.com/bug.php?id=55568http://dev.mysql.com/doc/refman/5.0/en/news-5-0-92.htmlhttp://dev.mysql.com/doc/refman/5.1/en/news-5-1-51.htmlhttp://dev.mysql.com/doc/refman/5.5/en/news-5-5-6.htmlhttp://lists.apple.com/archives/security-announce/2011//Jun/msg00000.htmlhttp://secunia.com/advisories/42875http://support.apple.com/kb/HT4723http://www.debian.org/security/2011/dsa-2143http://www.mandriva.com/security/advisories?name=MDVSA-2010:222http://www.mandriva.com/security/advisories?name=MDVSA-2010:223http://www.securityfocus.com/bid/43676http://www.turbolinux.co.jp/security/2011/TLSA-2011-3j.txthttp://www.ubuntu.com/usn/USN-1017-1http://www.ubuntu.com/usn/USN-1397-1http://www.vupen.com/english/advisories/2011/0105http://www.vupen.com/english/advisories/2011/0345https://bugzilla.redhat.com/show_bug.cgi?id=640808https://exchange.xforce.ibmcloud.com/vulnerabilities/64844http://bugs.mysql.com/bug.php?id=55568http://dev.mysql.com/doc/refman/5.0/en/news-5-0-92.htmlhttp://dev.mysql.com/doc/refman/5.1/en/news-5-1-51.htmlhttp://dev.mysql.com/doc/refman/5.5/en/news-5-5-6.htmlhttp://lists.apple.com/archives/security-announce/2011//Jun/msg00000.htmlhttp://secunia.com/advisories/42875http://support.apple.com/kb/HT4723http://www.debian.org/security/2011/dsa-2143http://www.mandriva.com/security/advisories?name=MDVSA-2010:222http://www.mandriva.com/security/advisories?name=MDVSA-2010:223http://www.securityfocus.com/bid/43676http://www.turbolinux.co.jp/security/2011/TLSA-2011-3j.txthttp://www.ubuntu.com/usn/USN-1017-1http://www.ubuntu.com/usn/USN-1397-1http://www.vupen.com/english/advisories/2011/0105http://www.vupen.com/english/advisories/2011/0345https://bugzilla.redhat.com/show_bug.cgi?id=640808https://exchange.xforce.ibmcloud.com/vulnerabilities/64844
2011-01-14
Published