CVE-2006-1518
medium · 6.5Buffer overflow in the open_table function in sql_base.cc in MySQL 5.0.x up to 5.0.20 might allow remote attackers to execute arbitrary code via crafted COM_TABLE_DUMP packets with invalid length values.
6.5
CVSS
38.4%
EPSS (exploit prob.)
98th
EPSS percentile
2006-05-05
Published
AV:N/AC:L/Au:S/C:P/I:P/A:P
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| mysql | mysql | 5.0.1 |
| mysql | mysql | 5.0.2 |
| mysql | mysql | 5.0.3 |
| mysql | mysql | 5.0.4 |
| mysql | mysql | 5.0.5 |
| mysql | mysql | 5.0.10 |
| mysql | mysql | 5.0.15 |
| mysql | mysql | 5.0.16 |
| mysql | mysql | 5.0.17 |
| mysql | mysql | 5.0.20 |
| oracle | mysql | 5.0.0 |
| oracle | mysql | 5.0.3 |
| oracle | mysql | 5.0.6 |
| oracle | mysql | 5.0.7 |
| oracle | mysql | 5.0.8 |
| oracle | mysql | 5.0.9 |
| oracle | mysql | 5.0.11 |
| oracle | mysql | 5.0.12 |
| oracle | mysql | 5.0.13 |
| oracle | mysql | 5.0.14 |
| oracle | mysql | 5.0.18 |
| oracle | mysql | 5.0.19 |
Check a specific version with /api/v1/cve/match.
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=365939
- http://dev.mysql.com/doc/refman/5.0/en/news-5-0-21.html
- http://lists.suse.com/archive/suse-security-announce/2006-Jun/0011.html
- http://secunia.com/advisories/19929
- http://secunia.com/advisories/20241
- http://secunia.com/advisories/20253
- http://secunia.com/advisories/20333
- http://secunia.com/advisories/20457
- http://secunia.com/advisories/20762
- http://securityreason.com/securityalert/839
- http://securitytracker.com/id?1016016
- http://www.debian.org/security/2006/dsa-1071
- http://www.debian.org/security/2006/dsa-1073
- http://www.debian.org/security/2006/dsa-1079
- http://www.kb.cert.org/vuls/id/602457
- http://www.novell.com/linux/security/advisories/2006-06-02.html
- http://www.securityfocus.com/archive/1/432734/100/0/threaded
- http://www.securityfocus.com/bid/17780
- http://www.vupen.com/english/advisories/2006/1633
- http://www.wisec.it/vulns.php?page=8
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26232
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=365939
- http://dev.mysql.com/doc/refman/5.0/en/news-5-0-21.html
- http://lists.suse.com/archive/suse-security-announce/2006-Jun/0011.html
- http://secunia.com/advisories/19929
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2006-1518