MySQL 5.0 before 5.0.66, 5.1 before 5.1.26, and 6.0 before 6.0.6 does not properly handle a b'' (b single-quote single-quote) token, aka an empty bit-string literal, which allows remote attackers to cause a denial of service (daemon crash) by using this token in a SQL statement.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2008-09-10 18:13
Updated : 2019-12-17 12:26
NVD link : CVE-2008-3963
Mitre link : CVE-2008-3963
JSON object : View
CWE
CWE-134
Use of Externally-Controlled Format String
Products Affected
oracle
- mysql
mysql
- mysql