Vulnerabilities > CVE-2004-2149 - Remote Buffer Overflow vulnerability in MySQL Bounded Parameter Statement Execution

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
oracle
nessus

Summary

Buffer overflow in the prepared statements API in libmysqlclient for MySQL 4.1.3 beta and 4.1.4 allows remote attackers to cause a denial of service via a large number of placeholders.

Vulnerable Configurations

Part Description Count
Application
Oracle
2

Nessus

NASL familyDatabases
NASL idMYSQL_BOUNDED_PARAM_OVERFLOW.NASL
descriptionYou are running a version of MySQL 4.1.x, which is older than version 4.1.5. There is a flaw in the remote version of this software that could allow an attacker to crash the affected service, thus denying access to legitimate users.
last seen2020-06-01
modified2020-06-02
plugin id14831
published2004-09-27
reporterThis script is Copyright (C) 2004-2018 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/14831
titleMySQL libmysqlclient Prepared Statements API Overflow