CVE-2007-2583
The in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40, and 5.1 before 5.1.18-beta, allows context-dependent attackers to cause a denial of service (crash) via a crafted IF clause that results in a divide-by-zero error and a NULL pointer…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 11.3%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
The in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40, and 5.1 before 5.1.18-beta, allows context-dependent attackers to cause a denial of service (crash) via a crafted IF clause that results in a divide-by-zero error and a NULL pointer dereference.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
- EPSS
- 11.31% probability · 96th percentile
- CISA KEV
- Not listed
- Affected
- oracle/mysql · debian/debian linux · canonical/ubuntu linux
- Source
- cve@mitre.org
References
- http://bugs.mysql.com/bug.php?id=27513Issue Tracking, Vendor Advisory
- http://lists.mysql.com/commits/23685Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.htmlMailing List, Third Party Advisory
- http://packetstormsecurity.com/files/124295/MySQL-5.0.x-Denial-Of-Service.htmlThird Party Advisory, VDB Entry
- http://secunia.com/advisories/25188Vendor Advisory
- http://secunia.com/advisories/25196Patch, Vendor Advisory
- http://secunia.com/advisories/25255Vendor Advisory
- http://secunia.com/advisories/25389Vendor Advisory
- http://secunia.com/advisories/25946Vendor Advisory
- http://secunia.com/advisories/27155Vendor Advisory
- http://secunia.com/advisories/27823Vendor Advisory
- http://secunia.com/advisories/28838Vendor Advisory
- http://secunia.com/advisories/30351Vendor Advisory
- http://security.gentoo.org/glsa/glsa-200705-11.xmlThird Party Advisory
- http://www.debian.org/security/2007/dsa-1413Patch, Third Party Advisory
- http://www.exploit-db.com/exploits/30020Third Party Advisory, VDB Entry
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:139Third Party Advisory
- http://www.osvdb.org/34734Broken Link
- http://www.redhat.com/support/errata/RHSA-2008-0364.htmlVendor Advisory
- http://www.securityfocus.com/bid/23911Third Party Advisory, VDB Entry, Vendor Advisory
- http://www.trustix.org/errata/2007/0017/Broken Link
- http://www.vupen.com/english/advisories/2007/1731Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34232Third Party Advisory, VDB Entry
- https://issues.rpath.com/browse/RPL-1356Broken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9930Third Party Advisory
- https://usn.ubuntu.com/528-1/Third Party Advisory
- http://bugs.mysql.com/bug.php?id=27513Issue Tracking, Vendor Advisory
- http://lists.mysql.com/commits/23685Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.htmlMailing List, Third Party Advisory
- http://packetstormsecurity.com/files/124295/MySQL-5.0.x-Denial-Of-Service.htmlThird Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.