CVE Vulnerabilities

CVE-2009-0819

Published: Mar 05, 2009 | Modified: Dec 17, 2019
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

sql/item_xmlfunc.cc in MySQL 5.1 before 5.1.32 and 6.0 before 6.0.10 allows remote authenticated users to cause a denial of service (crash) via an XPath expression employing a scalar expression as a FilterExpr with ExtractValue() or UpdateXML(), which triggers an assertion failure.

Affected Software

Name Vendor Start Version End Version
Mysql Mysql 5.1.23 5.1.23
Mysql Mysql 6.0.9 6.0.9
Mysql Mysql * 5.1.32-bzr
Mysql Mysql 5.1.31 5.1.31
Mysql Mysql 6.0.10-bzr 6.0.10-bzr
Mysql Oracle 6.0.0 6.0.0
Mysql Oracle 6.0.1 6.0.1
Mysql Oracle 6.0.2 6.0.2
Mysql Oracle 6.0.3 6.0.3
Mysql Oracle 6.0.4 6.0.4
Mysql Oracle 5.1 5.1
Mysql Oracle 5.1.1 5.1.1
Mysql Oracle 5.1.2 5.1.2
Mysql Oracle 5.1.3 5.1.3
Mysql Oracle 5.1.10 5.1.10
Mysql Oracle 5.1.11 5.1.11
Mysql Oracle 5.1.12 5.1.12
Mysql Oracle 5.1.13 5.1.13
Mysql Oracle 5.1.14 5.1.14
Mysql Oracle 5.1.15 5.1.15
Mysql Oracle 5.1.16 5.1.16
Mysql Oracle 5.1.17 5.1.17
Mysql Oracle 5.1.18 5.1.18
Mysql Oracle 5.1.19 5.1.19
Mysql Oracle 5.1.20 5.1.20
Mysql Oracle 5.1.21 5.1.21
Mysql Oracle 5.1.22 5.1.22
Mysql Oracle 5.1.24 5.1.24
Mysql Oracle 5.1.25 5.1.25
Mysql Oracle 5.1.26 5.1.26
Mysql Oracle 5.1.27 5.1.27
Mysql Oracle 5.1.28 5.1.28
Mysql Oracle 5.1.29 5.1.29
Mysql Oracle 5.1.30 5.1.30
Mysql Oracle 5.1.23 5.1.23
Mysql Oracle 5.1.31 5.1.31

References