CVE Vulnerabilities

CVE-2009-0819

Published: Mar 05, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

sql/item_xmlfunc.cc in MySQL 5.1 before 5.1.32 and 6.0 before 6.0.10 allows remote authenticated users to cause a denial of service (crash) via an XPath expression employing a scalar expression as a FilterExpr with ExtractValue() or UpdateXML(), which triggers an assertion failure.

Affected Software

NameVendorStart VersionEnd Version
MysqlMysql*5.1.32-bzr (including)
MysqlMysql5.1.23 (including)5.1.23 (including)
MysqlMysql5.1.31 (including)5.1.31 (including)
MysqlMysql6.0.9 (including)6.0.9 (including)
MysqlMysql6.0.10-bzr (including)6.0.10-bzr (including)
MysqlOracle5.1 (including)5.1 (including)
MysqlOracle5.1.1 (including)5.1.1 (including)
MysqlOracle5.1.2 (including)5.1.2 (including)
MysqlOracle5.1.3 (including)5.1.3 (including)
MysqlOracle5.1.10 (including)5.1.10 (including)
MysqlOracle5.1.11 (including)5.1.11 (including)
MysqlOracle5.1.12 (including)5.1.12 (including)
MysqlOracle5.1.13 (including)5.1.13 (including)
MysqlOracle5.1.14 (including)5.1.14 (including)
MysqlOracle5.1.15 (including)5.1.15 (including)
MysqlOracle5.1.16 (including)5.1.16 (including)
MysqlOracle5.1.17 (including)5.1.17 (including)
MysqlOracle5.1.18 (including)5.1.18 (including)
MysqlOracle5.1.19 (including)5.1.19 (including)
MysqlOracle5.1.20 (including)5.1.20 (including)
MysqlOracle5.1.21 (including)5.1.21 (including)
MysqlOracle5.1.22 (including)5.1.22 (including)
MysqlOracle5.1.23-a (including)5.1.23-a (including)
MysqlOracle5.1.24 (including)5.1.24 (including)
MysqlOracle5.1.25 (including)5.1.25 (including)
MysqlOracle5.1.26 (including)5.1.26 (including)
MysqlOracle5.1.27 (including)5.1.27 (including)
MysqlOracle5.1.28 (including)5.1.28 (including)
MysqlOracle5.1.29 (including)5.1.29 (including)
MysqlOracle5.1.30 (including)5.1.30 (including)
MysqlOracle5.1.31-sp1 (including)5.1.31-sp1 (including)
MysqlOracle6.0.0 (including)6.0.0 (including)
MysqlOracle6.0.1 (including)6.0.1 (including)
MysqlOracle6.0.2 (including)6.0.2 (including)
MysqlOracle6.0.3 (including)6.0.3 (including)
MysqlOracle6.0.4 (including)6.0.4 (including)
Mysql-dfsg-5.0Ubuntugutsy*
Mysql-dfsg-5.0Ubuntuupstream*
Mysql-dfsg-5.1Ubuntujaunty*
Mysql-dfsg-5.1Ubuntuupstream*

References