sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attackers to obtain sensitive information via a COM_TABLE_DUMP request with an incorrect packet length, which includes portions of memory in an error message.

Project Subscriptions

Vendors Products
Enterprise Linux Subscribe
Advisories
Source ID Title
Debian DSA Debian DSA DSA-1071-1 New MySQL 3.23 packages fix several vulnerabilities
Debian DSA Debian DSA DSA-1073-1 New MySQL 4.1 packages fix several vulnerabilities
Debian DSA Debian DSA DSA-1079-1 New MySQL 4.0 packages fix several vulnerabilities
EUVD EUVD EUVD-2006-1521 sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attackers to obtain sensitive information via a COM_TABLE_DUMP request with an incorrect packet length, which includes portions of memory in an error message.
Ubuntu USN Ubuntu USN USN-283-1 MySQL vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=365939 cve-icon cve-icon
http://dev.mysql.com/doc/refman/5.0/en/news-5-0-21.html cve-icon cve-icon
http://docs.info.apple.com/article.html?artnum=305214 cve-icon cve-icon
http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html cve-icon cve-icon
http://lists.suse.com/archive/suse-security-announce/2006-Jun/0011.html cve-icon cve-icon
http://secunia.com/advisories/19929 cve-icon cve-icon
http://secunia.com/advisories/20002 cve-icon cve-icon
http://secunia.com/advisories/20073 cve-icon cve-icon
http://secunia.com/advisories/20076 cve-icon cve-icon
http://secunia.com/advisories/20223 cve-icon cve-icon
http://secunia.com/advisories/20241 cve-icon cve-icon
http://secunia.com/advisories/20253 cve-icon cve-icon
http://secunia.com/advisories/20333 cve-icon cve-icon
http://secunia.com/advisories/20424 cve-icon cve-icon
http://secunia.com/advisories/20457 cve-icon cve-icon
http://secunia.com/advisories/20625 cve-icon cve-icon
http://secunia.com/advisories/20762 cve-icon cve-icon
http://secunia.com/advisories/24479 cve-icon cve-icon
http://secunia.com/advisories/29847 cve-icon cve-icon
http://securityreason.com/securityalert/839 cve-icon cve-icon
http://securitytracker.com/id?1016016 cve-icon cve-icon
http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.599377 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-26-236703-1 cve-icon cve-icon
http://www.debian.org/security/2006/dsa-1071 cve-icon cve-icon
http://www.debian.org/security/2006/dsa-1073 cve-icon cve-icon
http://www.debian.org/security/2006/dsa-1079 cve-icon cve-icon
http://www.gentoo.org/security/en/glsa/glsa-200605-13.xml cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2006:084 cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2006-06-02.html cve-icon cve-icon
http://www.osvdb.org/25228 cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2006-0544.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/432734/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/434164/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/17780 cve-icon cve-icon
http://www.trustix.org/errata/2006/0028 cve-icon cve-icon
http://www.us-cert.gov/cas/techalerts/TA07-072A.html cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/1633 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/0930 cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/1326/references cve-icon cve-icon
http://www.wisec.it/vulns.php?page=8 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/26228 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2006-1517 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11036 cve-icon cve-icon
https://usn.ubuntu.com/283-1/ cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2006-1517 cve-icon
History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: debian

Published:

Updated: 2024-08-07T17:12:22.483Z

Reserved: 2006-03-30T05:00:00.000Z

Link: CVE-2006-1517

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2006-05-05T12:46:00.000

Modified: 2025-04-03T01:03:51.193

Link: CVE-2006-1517

cve-icon Redhat

Severity : Moderate

Publid Date: 2006-05-02T00:00:00Z

Links: CVE-2006-1517 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses