Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (crash) via (1) IN or (2) CASE operations with NULL arguments that are explicitly specified or indirectly provided by the WITH ROLLUP modifier.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade dev-db/mysql. | Oct 30, 2017 | Jan 11, 2011 |
| Oracle Mysql | — | Upgrade to Oracle MySQL version 5.1.49 | Aug 29, 2012 | Jan 11, 2011 |
| Oracle_linux | — | Upgrade mysql-testUpgrade mysql-develUpgrade mysql-serverUpgrade mysqlUpgrade mysql-benchUpgrade mysql-libsUpgrade mysql-embeddedUpgrade mysql-embedded-devel | Oct 16, 2024 | Jan 11, 2011 |
| Suse | — | Upgrade libmysqlclient_r15Upgrade libmysqlclient15-32bitUpgrade mysql-MaxUpgrade libmysqlclient15Upgrade mysql-clientUpgrade libmysqlclient15-x86Upgrade mysql | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade mysql-server-5.1Upgrade mysql-server-5.0 | Nov 8, 2024 | Jan 11, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub