DSA-1877 mysql-dfsg-5.0 -- denial of service/execution of arbitrary codeID: oval:org.mitre.oval:def:7905 | Date: (C)2009-12-15 (M)2023-12-07 |
Class: PATCH | Family: unix |
In MySQL 4.0.0 through 5.0.83, multiple format string vulnerabilities in the dispatch_command() function in libmysqld/sql_parse.cc in mysqld allow remote authenticated users to cause a denial of service (daemon crash) and potentially the execution of arbitrary code via format string specifiers in a database name in a COM_CREATE_DB or COM_DROP_DB request.
Platform: |
Debian 5.0 |
Debian 4.0 |