Vulnerabilities > CVE-2005-0799 - Denial-Of-Service vulnerability in Oracle Mysql 4.1.9

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
oracle
nessus

Summary

MySQL 4.1.9, and possibly earlier versions, allows remote attackers with certain privileges to cause a denial of service (application crash) via a use command followed by an MS-DOS device name such as (1) LPT1 or (2) PRN.

Vulnerable Configurations

Part Description Count
Application
Oracle
1

Nessus

NASL familyDatabases
NASL idMYSQL_4_1_13_OR_5_0_8.NASL
descriptionThe version of MySQL installed on the remote host is older than 4.1.13 or 5.0.8. On Windows, a remote attacker can crash the server via a
last seen2020-06-01
modified2020-06-02
plugin id17826
published2012-01-18
reporterThis script is Copyright (C) 2012-2018 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/17826
titleMySQL < 4.1.13 / 5.0.8 DOS Device Name Denial of Service Vulnerabilities