MySQL convert_search_mode_to_innobase() Bug Lets Remote Authenticated Users Deny Service
|
|
SecurityTracker Alert ID: 1018978
|
|
SecurityTracker URL: http://securitytracker.com/id?1018978
|
|
CVE Reference: CVE-2007-5925
(Links to External Site)
|
Date: Nov 19 2007
|
Impact: Denial of service via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Version(s): 5.1.23-BK and prior versions
|
Description: A vulnerability was reported in MySQL. A remote authenticated user can cause denial of service conditions.
A remote authenticated user can send specially crafted request to trigger an assertion error in the convert_search_mode_to_innobase()
function and cause the target service to crash.
The vulnerable function resides in 'ha_innodb.cc'.
A specially crafted CONTAINS
operation on an indexed column can trigger the flaw.
Artem Russakovskii reported this vulnerability.
|
Impact: A remote authenticated user can cause denial of service conditions on the target system.
|
Solution: The vendor has issued a fix.
A source code patch is available at:
bugs.mysql.com/bug.php?id=32125
|
Vendor URL: bugs.mysql.com/bug.php?id=32125 (Links to External Site)
|
Cause: Input validation error
|
Underlying OS: Linux (Any), UNIX (Any), Windows (Any)
|
Reported By: "Kristian Erik Hermansen" <kristian.hermansen@gmail.com>
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Mon, 5 Nov 2007 22:38:36 -0800
From: "Kristian Erik Hermansen" <kristian.hermansen@gmail.com>
Subject: [Full-disclosure] MySQL 5.x DoS (unknown)
|
My roommate Joe Gallo found this one today while tediously laboring
away at blinkx (video search engine), but I think it is funny, and
could be used to crash local/remote databases due to an assertion in
MySQL that fails and results in SIGABRT/signal-6 to occur on
non-indexed tables...have phun :-)
http://bugs.mysql.com/bug.php?id=32125
--
Kristian Erik Hermansen
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
|
|