CVE
- Id
- 41454
- CVE No.
- CVE-2009-4019
- Status
- Candidate
- Description
- mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of certain SELECT statements with subqueries, and does not (2) preserve certain null_value flags during execution of statements that use the GeomFromWKB function, which allows remote authenticated users to cause a denial of service (daemon crash) via a crafted statement.
- Phase
- Assigned (20091120)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
455321 | 41454 | CVE-2009-4019 | MLIST:[oss-security] 20091121 CVE Request - MySQL - 5.0.88 | View |
455322 | 41454 | CVE-2009-4019 | URL:http://marc.info/?l=oss-security&m=125881733826437&w=2 | View |
455323 | 41454 | CVE-2009-4019 | MLIST:[oss-security] 20091121 Re: CVE Request - MySQL - 5.0.88 | View |
455324 | 41454 | CVE-2009-4019 | URL:http://marc.info/?l=oss-security&m=125883754215621&w=2 | View |
455325 | 41454 | CVE-2009-4019 | MLIST:[oss-security] 20091123 Re: CVE Request - MySQL - 5.0.88 | View |
455326 | 41454 | CVE-2009-4019 | URL:http://marc.info/?l=oss-security&m=125901161824278&w=2 | View |
455327 | 41454 | CVE-2009-4019 | CONFIRM:http://bugs.mysql.com/47780 | View |
455328 | 41454 | CVE-2009-4019 | CONFIRM:http://bugs.mysql.com/48291 | View |
455329 | 41454 | CVE-2009-4019 | CONFIRM:http://dev.mysql.com/doc/refman/5.0/en/news-5-0-88.html | View |
455330 | 41454 | CVE-2009-4019 | CONFIRM:http://dev.mysql.com/doc/refman/5.1/en/news-5-1-41.html | View |
455331 | 41454 | CVE-2009-4019 | CONFIRM:https://bugzilla.redhat.com/show_bug.cgi?id=540906 | View |
455332 | 41454 | CVE-2009-4019 | CONFIRM:http://support.apple.com/kb/HT4077 | View |
455333 | 41454 | CVE-2009-4019 | APPLE:APPLE-SA-2010-03-29-1 | View |
455334 | 41454 | CVE-2009-4019 | URL:http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html | View |
455335 | 41454 | CVE-2009-4019 | DEBIAN:DSA-1997 | View |
455336 | 41454 | CVE-2009-4019 | URL:http://www.debian.org/security/2010/dsa-1997 | View |
455337 | 41454 | CVE-2009-4019 | FEDORA:FEDORA-2009-12180 | View |
455338 | 41454 | CVE-2009-4019 | URL:https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00764.html | View |
455339 | 41454 | CVE-2009-4019 | REDHAT:RHSA-2010:0109 | View |
455340 | 41454 | CVE-2009-4019 | URL:http://www.redhat.com/support/errata/RHSA-2010-0109.html | View |
455341 | 41454 | CVE-2009-4019 | SUSE:SUSE-SR:2010:011 | View |
455342 | 41454 | CVE-2009-4019 | URL:http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html | View |
455343 | 41454 | CVE-2009-4019 | UBUNTU:USN-897-1 | View |
455344 | 41454 | CVE-2009-4019 | URL:http://ubuntu.com/usn/usn-897-1 | View |
455345 | 41454 | CVE-2009-4019 | OVAL:oval:org.mitre.oval:def:11349 | View |
455346 | 41454 | CVE-2009-4019 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11349 | View |
455347 | 41454 | CVE-2009-4019 | OVAL:oval:org.mitre.oval:def:8500 | View |
455348 | 41454 | CVE-2009-4019 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8500 | View |
455349 | 41454 | CVE-2009-4019 | SECUNIA:37717 | View |
455350 | 41454 | CVE-2009-4019 | URL:http://secunia.com/advisories/37717 | View |
455351 | 41454 | CVE-2009-4019 | SECUNIA:38573 | View |
455352 | 41454 | CVE-2009-4019 | URL:http://secunia.com/advisories/38573 | View |
455353 | 41454 | CVE-2009-4019 | SECUNIA:38517 | View |
455354 | 41454 | CVE-2009-4019 | URL:http://secunia.com/advisories/38517 | View |
455355 | 41454 | CVE-2009-4019 | VUPEN:ADV-2010-1107 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
44125 | JVNDB-2009-005132 | PEAR の Mail パッケージにおける任意のファイルを読まれる脆弱性 | PEAR の Mail パッケージの Mail::Send メソッド (Mail/sendmail.php) の sendmail の実装は、引数の挿入により、任意のファイルを読まれる、および書き込まれる脆弱性が存在します。 | CVE-2009-4023 | 41454 | 7.5 | http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-005132.html | View |