DB: MySQL Single Row Denial Of Service

This signature detects attempts to exploit a known vulnerability against MySQl database. A successful attack can result in a denial-of-service condition.

Extended Description

MySQL is prone to a remote denial-of-service vulnerability because it fails to handle certain select statements to database metadata. An attacker can exploit this issue to crash the application, denying access to legitimate users. The attacker may also be able to execute arbitrary code, but this has not yet been confirmed. NOTE: An attacker must be able to execute arbitrary SELECT statements on the vulnerable computer to exploit this issue. This may be through legitimate means or by exploiting other latent SQL-injection vulnerabilities. Versions prior to 5.0.36 are vulnerable.

Affected Products

Mandriva corporate_server

Short Name
DB:MYSQL:SINGLE-ROW-DOS
Severity
Major
Recommended
False
Recommended Action
Drop
Category
DB
Keywords
CVE-2007-1420 Denial MySQL Of Row Service Single bid:22900
Release Date
03/19/2007
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Red_hat

Mysql_ab

Gentoo

Rpath

Pardus

Ubuntu

Mandriva

CVSS Score

2.1

Found a potential security threat?