MySQL 5.0 before 5.0.66, 5.1 before 5.1.26, and 6.0 before 6.0.6 does not properly handle a b'' (b single-quote single-quote) token, aka an empty bit-string literal, which allows remote attackers to cause a denial of service (daemon crash) by using this token in a SQL statement.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2008-09-11 01:13
Updated : 2019-12-17 20:26
NVD link : CVE-2008-3963
Mitre link : CVE-2008-3963
CVE.ORG link : CVE-2008-3963
JSON object : View
Products Affected
mysql
- mysql
oracle
- mysql
CWE
CWE-134
Use of Externally-Controlled Format String