mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of certain SELECT statements with subqueries, and does not (2) preserve certain null_value flags during execution of statements that use the GeomFromWKB function, which allows remote authenticated users to cause a denial of service (daemon crash) via a crafted statement.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1997-1 | New mysql-dfsg-5.0 packages fix several vulnerabilities |
Ubuntu USN |
USN-897-1 | MySQL vulnerabilities |
Ubuntu USN |
USN-1397-1 | MySQL vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T06:45:50.912Z
Reserved: 2009-11-20T00:00:00
Link: CVE-2009-4019
No data.
Status : Deferred
Published: 2009-11-30T17:30:00.250
Modified: 2025-04-09T00:30:58.490
Link: CVE-2009-4019
OpenCVE Enrichment
No data.
Debian DSA
Ubuntu USN