Vulnerabilities > CVE-2001-1274 - Unspecified vulnerability in Oracle Mysql

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
oracle
nessus
exploit available

Summary

Buffer overflow in MySQL before 3.23.31 allows attackers to cause a denial of service and possibly gain privileges.

Exploit-Db

descriptionMysql 3.22.x/3.23.x Local Buffer Overflow Vulnerability. CVE-2001-1274. Local exploit for linux platform
idEDB-ID:20581
last seen2016-02-02
modified2001-01-18
published2001-01-18
reporterLuis Miguel Silva
sourcehttps://www.exploit-db.com/download/20581/
titleMysql 3.22.x/3.23.x - Local Buffer Overflow Vulnerability

Nessus

  • NASL familyDatabases
    NASL idMYSQL_3_23_31.NASL
    descriptionThe version of MySQL installed on the remote host allows a remote attacker to exploit a buffer overflow and crash the server, or even execute arbitrary code.
    last seen2020-06-01
    modified2020-06-02
    plugin id17817
    published2012-01-18
    reporterThis script is Copyright (C) 2012-2018 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/17817
    titleMySQL < 3.23.31 Buffer Overflow
  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DSA-013.NASL
    descriptionNicolas Gregoire has reported a buffer overflow in the mysql server that leads to a remote exploit. An attacker could gain mysqld privileges (and thus gaining access to all the databases).
    last seen2020-06-01
    modified2020-06-02
    plugin id14850
    published2004-09-29
    reporterThis script is Copyright (C) 2004-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/14850
    titleDebian DSA-013 : MySQL - remote buffer overflow
  • NASL familyMandriva Local Security Checks
    NASL idMANDRAKE_MDKSA-2001-014.NASL
    descriptionA security problem exists in all versions of MySQL after 3.23.2 and prior to 3.23.31. The problem is that the SHOW GRANTS command could be executed by any user making it possible for anyone with a MySQL account to get the crypted password from the mysql.user table. The new 3.23.31 version fixes this. Due to library changes, the previously announced PHP update (MDKSA-2001:013) has been updated as well so that the php-mysql module supports this new version of MySQL. It also corrects the upgrade scripts in the package, however you will still need to verify that PHP support is enabled in your /etc/httpd/conf/httpd.conf Apache configuration file and verify that the installed modules are uncommented in your /etc/php.ini file. Update : Previous versions of MySQL also suffered from a buffer overflow problem that has been corrected in the recent releases. This update fixes the buffer overflow problem in the MySQL packages provided with Linux- Mandrake 7.1 and Corporate Server 1.0.1.
    last seen2020-06-01
    modified2020-06-02
    plugin id61888
    published2012-09-06
    reporterThis script is Copyright (C) 2012-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/61888
    titleMandrake Linux Security Advisory : MySQL (MDKSA-2001:014-1)

Redhat

advisories
rhsa
idRHSA-2001:003