CVE-2007-1420
LOW severity · CVSS 2.1
2.1CVSS LOW
Summary
MySQL 5.x before 5.0.36 allows local users to cause a denial of service (database crash) by performing information_schema table subselects and using ORDER BY to sort a single-row result, which prevents certain structure elements from being initialized and triggers a NULL dereference in the filesort function.
Impact & exploitability
Attack vectorLocal
Attack complexityLow
Privileges required—
User interaction—
Confidentiality impactNone
Integrity impactNone
Availability impact—
Exploit probability (EPSS)1%
AV:L/AC:L/Au:N/C:N/I:N/A:P
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Additional information
- NVD record
- http://dev.mysql.com/doc/refman/5.0/en/releasenotes-es-5-0-36.htmlAdvisory
- http://secunia.com/advisories/24483Advisory
- http://secunia.com/advisories/24609Advisory
- http://secunia.com/advisories/25196Advisory
- http://secunia.com/advisories/25389Advisory
- http://secunia.com/advisories/25946Advisory
- http://secunia.com/advisories/30351Advisory
- http://bugs.mysql.com/bug.php?id=24630