CVE Vulnerabilities

CVE-2010-3682

Published: Jan 11, 2011 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V2
4 MODERATE
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Oracle MySQL 5.1 before 5.1.49 and 5.0 before 5.0.92 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by using EXPLAIN with crafted SELECT … UNION … ORDER BY (SELECT … WHERE …) statements, which triggers a NULL pointer dereference in the Item_singlerow_subselect::store function.

Affected Software

NameVendorStart VersionEnd Version
MysqlMysql*5.1.48 (including)
MysqlMysql5.1.23 (including)5.1.23 (including)
MysqlMysql5.1.31 (including)5.1.31 (including)
MysqlMysql5.1.32 (including)5.1.32 (including)
MysqlMysql5.1.34 (including)5.1.34 (including)
MysqlMysql5.1.37 (including)5.1.37 (including)
MysqlOracle5.1.1 (including)5.1.1 (including)
MysqlOracle5.1.2 (including)5.1.2 (including)
MysqlOracle5.1.3 (including)5.1.3 (including)
MysqlOracle5.1.4 (including)5.1.4 (including)
MysqlOracle5.1.10 (including)5.1.10 (including)
MysqlOracle5.1.11 (including)5.1.11 (including)
MysqlOracle5.1.12 (including)5.1.12 (including)
MysqlOracle5.1.13 (including)5.1.13 (including)
MysqlOracle5.1.14 (including)5.1.14 (including)
MysqlOracle5.1.15 (including)5.1.15 (including)
MysqlOracle5.1.16 (including)5.1.16 (including)
MysqlOracle5.1.17 (including)5.1.17 (including)
MysqlOracle5.1.18 (including)5.1.18 (including)
MysqlOracle5.1.19 (including)5.1.19 (including)
MysqlOracle5.1.20 (including)5.1.20 (including)
MysqlOracle5.1.21 (including)5.1.21 (including)
MysqlOracle5.1.22 (including)5.1.22 (including)
MysqlOracle5.1.23-a (including)5.1.23-a (including)
MysqlOracle5.1.24 (including)5.1.24 (including)
MysqlOracle5.1.25 (including)5.1.25 (including)
MysqlOracle5.1.26 (including)5.1.26 (including)
MysqlOracle5.1.27 (including)5.1.27 (including)
MysqlOracle5.1.28 (including)5.1.28 (including)
MysqlOracle5.1.29 (including)5.1.29 (including)
MysqlOracle5.1.30 (including)5.1.30 (including)
MysqlOracle5.1.31-sp1 (including)5.1.31-sp1 (including)
MysqlOracle5.1.33 (including)5.1.33 (including)
MysqlOracle5.1.34-sp1 (including)5.1.34-sp1 (including)
MysqlOracle5.1.35 (including)5.1.35 (including)
MysqlOracle5.1.36 (including)5.1.36 (including)
MysqlOracle5.1.37-sp1 (including)5.1.37-sp1 (including)
MysqlOracle5.1.38 (including)5.1.38 (including)
MysqlOracle5.1.39 (including)5.1.39 (including)
MysqlOracle5.1.40 (including)5.1.40 (including)
MysqlOracle5.1.40-sp1 (including)5.1.40-sp1 (including)
MysqlOracle5.1.41 (including)5.1.41 (including)
MysqlOracle5.1.42 (including)5.1.42 (including)
MysqlOracle5.1.43 (including)5.1.43 (including)
MysqlOracle5.1.43-sp1 (including)5.1.43-sp1 (including)
MysqlOracle5.1.44 (including)5.1.44 (including)
MysqlOracle5.1.45 (including)5.1.45 (including)
MysqlOracle5.1.46 (including)5.1.46 (including)
MysqlOracle5.1.46-sp1 (including)5.1.46-sp1 (including)
MysqlOracle5.1.47 (including)5.1.47 (including)
Red Hat Enterprise Linux 5RedHatmysql-0:5.0.77-4.el5_5.4*
Red Hat Enterprise Linux 6RedHatmysql-0:5.1.52-1.el6_0.1*
Mysql-5.1Ubuntuupstream*
Mysql-cluster-7.0Ubuntulucid*
Mysql-cluster-7.0Ubuntumaverick*
Mysql-cluster-7.0Ubuntunatty*
Mysql-cluster-7.0Ubuntuoneiric*
Mysql-dfsg-5.0Ubuntudapper*
Mysql-dfsg-5.0Ubuntuhardy*
Mysql-dfsg-5.0Ubuntukarmic*
Mysql-dfsg-5.1Ubuntukarmic*
Mysql-dfsg-5.1Ubuntulucid*
Mysql-dfsg-5.1Ubuntuupstream*

References