VulnerabilityModified
CVE-2004-0837
MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows attackers to cause a denial of service (crash or hang) via multiple threads that simultaneously alter MERGE table UNIONs.
LOW 2.6EPSS 4.90%
Does this matter?
Lower severity and a low EPSS score (4.90%). Track it; it rarely justifies an emergency change on its own.
Description
MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows attackers to cause a denial of service (crash or hang) via multiple threads that simultaneously alter MERGE table UNIONs.
- CVSS 2.0
- 2.6 LOWAV:N/AC:H/Au:N/C:N/I:N/A:P
- EPSS
- 4.90% probability · 92th percentile
- CISA KEV
- Not listed
- Affected
- mysql/mysql · oracle/mysql · debian/debian linux
- Source
- cve@mitre.org
References
- http://bugs.mysql.com/2408Exploit, Vendor Advisory
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000892Broken Link
- http://lists.mysql.com/internals/16168Vendor Advisory
- http://lists.mysql.com/internals/16173Vendor Advisory
- http://lists.mysql.com/internals/16174Vendor Advisory
- http://marc.info/?l=bugtraq&m=110140517515735&w=2Mailing List, Third Party Advisory
- http://mysql.bkbits.net:8080/mysql-3.23/diffs/myisammrg/myrg_open.c%401.15
- http://secunia.com/advisories/12783/Third Party Advisory
- http://securitytracker.com/id?1011606Third Party Advisory, VDB Entry
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-101864-1Broken Link
- http://www.ciac.org/ciac/bulletins/p-018.shtmlBroken Link
- http://www.debian.org/security/2004/dsa-562Third Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200410-22.xmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2004-597.htmlPatch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2004-611.htmlThird Party Advisory
- http://www.securityfocus.com/bid/11357Third Party Advisory, VDB Entry
- http://www.trustix.org/errata/2004/0054/Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17667Third Party Advisory, VDB Entry
- http://bugs.mysql.com/2408Exploit, Vendor Advisory
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000892Broken Link
- http://lists.mysql.com/internals/16168Vendor Advisory
- http://lists.mysql.com/internals/16173Vendor Advisory
- http://lists.mysql.com/internals/16174Vendor Advisory
- http://marc.info/?l=bugtraq&m=110140517515735&w=2Mailing List, Third Party Advisory
- http://mysql.bkbits.net:8080/mysql-3.23/diffs/myisammrg/myrg_open.c%401.15
- http://secunia.com/advisories/12783/Third Party Advisory
- http://securitytracker.com/id?1011606Third Party Advisory, VDB Entry
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-101864-1Broken Link
- http://www.ciac.org/ciac/bulletins/p-018.shtmlBroken Link
- http://www.debian.org/security/2004/dsa-562Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.