CVE
- Id
- 5758
- CVE No.
- CVE-2002-1374
- Status
- Entry
- Description
- The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x before 4.0.6, allows remote attackers to gain privileges via a brute force attack using a one-character password, which causes MySQL to only compare the provided password against the first character of the real password.
- Phase
- Votes
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
32104 | 5758 | CVE-2002-1374 | BUGTRAQ:20021212 Advisory 04/2002: Multiple MySQL vulnerabilities | View |
32105 | 5758 | CVE-2002-1374 | URL:http://marc.info/?l=bugtraq&m=103971644013961&w=2 | View |
32106 | 5758 | CVE-2002-1374 | MISC:http://security.e-matters.de/advisories/042002.html | View |
32107 | 5758 | CVE-2002-1374 | CONECTIVA:CLSA-2002:555 | View |
32108 | 5758 | CVE-2002-1374 | URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000555 | View |
32109 | 5758 | CVE-2002-1374 | DEBIAN:DSA-212 | View |
32110 | 5758 | CVE-2002-1374 | URL:http://www.debian.org/security/2002/dsa-212 | View |
32111 | 5758 | CVE-2002-1374 | ENGARDE:ESA-20021213-033 | View |
32112 | 5758 | CVE-2002-1374 | URL:http://www.linuxsecurity.com/advisories/engarde_advisory-2660.html | View |
32113 | 5758 | CVE-2002-1374 | GENTOO:GLSA-200212-2 | View |
32114 | 5758 | CVE-2002-1374 | URL:http://marc.info/?l=bugtraq&m=104004857201968&w=2 | View |
32115 | 5758 | CVE-2002-1374 | IMMUNIX:IMNX-2003-7+-008-01 | View |
32116 | 5758 | CVE-2002-1374 | URL:http://www.securityfocus.com/advisories/5269 | View |
32117 | 5758 | CVE-2002-1374 | MANDRAKE:MDKSA-2002:087 | View |
32118 | 5758 | CVE-2002-1374 | URL:http://www.mandrakesoft.com/security/advisories?name=MDKSA-2002:087 | View |
32119 | 5758 | CVE-2002-1374 | REDHAT:RHSA-2002:288 | View |
32120 | 5758 | CVE-2002-1374 | URL:http://www.redhat.com/support/errata/RHSA-2002-288.html | View |
32121 | 5758 | CVE-2002-1374 | REDHAT:RHSA-2002:289 | View |
32122 | 5758 | CVE-2002-1374 | URL:http://www.redhat.com/support/errata/RHSA-2002-289.html | View |
32123 | 5758 | CVE-2002-1374 | REDHAT:RHSA-2003:166 | View |
32124 | 5758 | CVE-2002-1374 | URL:http://www.redhat.com/support/errata/RHSA-2003-166.html | View |
32125 | 5758 | CVE-2002-1374 | SUSE:SUSE-SA:2003:003 | View |
32126 | 5758 | CVE-2002-1374 | URL:http://www.novell.com/linux/security/advisories/2003_003_mysql.html | View |
32127 | 5758 | CVE-2002-1374 | TRUSTIX:2002-0086 | View |
32128 | 5758 | CVE-2002-1374 | URL:http://www.trustix.net/errata/misc/2002/TSL-2002-0086-mysql.asc.txt | View |
32129 | 5758 | CVE-2002-1374 | BUGTRAQ:20021216 [OpenPKG-SA-2002.013] OpenPKG Security Advisory (mysql) | View |
32130 | 5758 | CVE-2002-1374 | URL:http://marc.info/?l=bugtraq&m=104005886114500&w=2 | View |
32131 | 5758 | CVE-2002-1374 | BID:6373 | View |
32132 | 5758 | CVE-2002-1374 | URL:http://www.securityfocus.com/bid/6373 | View |
32133 | 5758 | CVE-2002-1374 | XF:mysql-comchangeuser-password-bypass(10847) | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
63990 | JVNDB-2002-000317 | MySQL の COM_CHANGE_USER コマンドにおける特権を取得される脆弱性 | ------------ | CVE-2002-1374 | 5758 | 7.5 | http://jvndb.jvn.jp/ja/contents/2002/JVNDB-2002-000317.html | View |