CVE Vulnerabilities

CVE-2002-1374

Published: Dec 23, 2002 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x before 4.0.6, allows remote attackers to gain privileges via a brute force attack using a one-character password, which causes MySQL to only compare the provided password against the first character of the real password.

Affected Software

NameVendorStart VersionEnd Version
MysqlOracle3.22.26 (including)3.22.26 (including)
MysqlOracle3.22.27 (including)3.22.27 (including)
MysqlOracle3.22.28 (including)3.22.28 (including)
MysqlOracle3.22.29 (including)3.22.29 (including)
MysqlOracle3.22.30 (including)3.22.30 (including)
MysqlOracle3.22.32 (including)3.22.32 (including)
MysqlOracle3.23.2 (including)3.23.2 (including)
MysqlOracle3.23.3 (including)3.23.3 (including)
MysqlOracle3.23.4 (including)3.23.4 (including)
MysqlOracle3.23.5 (including)3.23.5 (including)
MysqlOracle3.23.8 (including)3.23.8 (including)
MysqlOracle3.23.9 (including)3.23.9 (including)
MysqlOracle3.23.10 (including)3.23.10 (including)
MysqlOracle3.23.23 (including)3.23.23 (including)
MysqlOracle3.23.24 (including)3.23.24 (including)
MysqlOracle3.23.25 (including)3.23.25 (including)
MysqlOracle3.23.26 (including)3.23.26 (including)
MysqlOracle3.23.27 (including)3.23.27 (including)
MysqlOracle3.23.28 (including)3.23.28 (including)
MysqlOracle3.23.29 (including)3.23.29 (including)
MysqlOracle3.23.30 (including)3.23.30 (including)
MysqlOracle3.23.31 (including)3.23.31 (including)
MysqlOracle3.23.34 (including)3.23.34 (including)
MysqlOracle3.23.36 (including)3.23.36 (including)
MysqlOracle3.23.37 (including)3.23.37 (including)
MysqlOracle3.23.38 (including)3.23.38 (including)
MysqlOracle3.23.39 (including)3.23.39 (including)
MysqlOracle3.23.40 (including)3.23.40 (including)
MysqlOracle3.23.41 (including)3.23.41 (including)
MysqlOracle3.23.42 (including)3.23.42 (including)
MysqlOracle3.23.43 (including)3.23.43 (including)
MysqlOracle3.23.44 (including)3.23.44 (including)
MysqlOracle3.23.45 (including)3.23.45 (including)
MysqlOracle3.23.46 (including)3.23.46 (including)
MysqlOracle3.23.47 (including)3.23.47 (including)
MysqlOracle3.23.48 (including)3.23.48 (including)
MysqlOracle3.23.49 (including)3.23.49 (including)
MysqlOracle3.23.50 (including)3.23.50 (including)
MysqlOracle3.23.51 (including)3.23.51 (including)
MysqlOracle3.23.52 (including)3.23.52 (including)
MysqlOracle3.23.53 (including)3.23.53 (including)
MysqlOracle3.23.53a (including)3.23.53a (including)
MysqlOracle4.0.0 (including)4.0.0 (including)
MysqlOracle4.0.1 (including)4.0.1 (including)
MysqlOracle4.0.2 (including)4.0.2 (including)
MysqlOracle4.0.3 (including)4.0.3 (including)
MysqlOracle4.0.5a (including)4.0.5a (including)
Netbackup_advanced_reporterSymantec_veritas3.4 (including)3.4 (including)
Netbackup_advanced_reporterSymantec_veritas4.5 (including)4.5 (including)
Netbackup_advanced_reporterSymantec_veritas4.5_fp1 (including)4.5_fp1 (including)
Netbackup_advanced_reporterSymantec_veritas4.5_fp2 (including)4.5_fp2 (including)
Netbackup_advanced_reporterSymantec_veritas4.5_fp3 (including)4.5_fp3 (including)
Netbackup_advanced_reporterSymantec_veritas4.5_mp1 (including)4.5_mp1 (including)
Netbackup_advanced_reporterSymantec_veritas4.5_mp2 (including)4.5_mp2 (including)
Netbackup_advanced_reporterSymantec_veritas4.5_mp3 (including)4.5_mp3 (including)
Netbackup_global_data_managerSymantec_veritas4.5 (including)4.5 (including)
Netbackup_global_data_managerSymantec_veritas4.5_fp1 (including)4.5_fp1 (including)
Netbackup_global_data_managerSymantec_veritas4.5_fp2 (including)4.5_fp2 (including)
Netbackup_global_data_managerSymantec_veritas4.5_fp3 (including)4.5_fp3 (including)
Netbackup_global_data_managerSymantec_veritas4.5_mp1 (including)4.5_mp1 (including)
Netbackup_global_data_managerSymantec_veritas4.5_mp2 (including)4.5_mp2 (including)
Netbackup_global_data_managerSymantec_veritas4.5_mp3 (including)4.5_mp3 (including)
Red Hat Enterprise Linux AS (Advanced Server) version 2.1RedHat*
Red Hat Linux 7.0RedHat*
Red Hat Linux 7.1RedHat*
Red Hat Linux 7.1RedHat*
Red Hat Linux 7.2RedHat*
Red Hat Linux 7.3RedHat*
Red Hat Linux 8.0RedHat*
Red Hat Linux Advanced Workstation 2.1RedHat*

References