DB: MySQL Database IN and CASE NULL Argument Denial of Service

This signature detects attempts to exploit a known vulnerability against MySQL database server. A successful attack can result in a denial-of-service condition.

Extended Description

Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (crash) via (1) IN or (2) CASE operations with NULL arguments that are explicitly specified or indirectly provided by the WITH ROLLUP modifier.

Affected Products

Oracle mysql

References

BugTraq: 42596

CVE: CVE-2010-3678

Short Name
DB:MYSQL:IN-NULL-ARG-DOS
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
DB
Keywords
Argument CASE CVE-2010-3678 Database Denial IN MySQL NULL Service and bid:42596 of
Release Date
10/26/2010
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Oracle

Mysql

CVSS Score

4.0

Found a potential security threat?