Oracle MySQL 5.1 before 5.1.49 and 5.0 before 5.0.92 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by using EXPLAIN with crafted "SELECT ... UNION ... ORDER BY (SELECT ... WHERE ...)" statements, which triggers a NULL pointer dereference in the Item_singlerow_subselect::store function.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2011-01-11T19:00:00
Updated: 2024-08-07T03:18:52.644Z
Reserved: 2010-09-28T00:00:00
Link: CVE-2010-3682
Vulnrichment
No data.
NVD
Status : Modified
Published: 2011-01-11T20:00:01.603
Modified: 2024-11-21T01:19:23.007
Link: CVE-2010-3682
Redhat