CVE 2010-3838
MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 allows remote authenticated users to cause a denial of service (server crash) via a query that uses the (1) GREATEST or (2) LEAST function with a mixed list of numeric and LONGBLOB arguments, which is not properly handled when the function's result is "processed using an intermediate temporary table."
Related bugs and status
CVE-2010-3838 (Candidate) is related to these bugs:
Bug #937869: MySQL security update tracking bug
Summary | In | Importance | Status | |||
---|---|---|---|---|---|---|
937869 | MySQL security update tracking bug | mysql-5.1 (Ubuntu) | Undecided | Fix Released | ||
937869 | MySQL security update tracking bug | mysql-5.1 (Ubuntu Maverick) | Undecided | Fix Released | ||
937869 | MySQL security update tracking bug | mysql-5.1 (Ubuntu Natty) | Undecided | Fix Released | ||
937869 | MySQL security update tracking bug | mysql-5.1 (Ubuntu Oneiric) | Undecided | Fix Released | ||
937869 | MySQL security update tracking bug | mysql-dfsg-5.1 (Ubuntu) | Undecided | Fix Released | ||
937869 | MySQL security update tracking bug | mysql-dfsg-5.1 (Ubuntu Maverick) | Undecided | Invalid | ||
937869 | MySQL security update tracking bug | mysql-dfsg-5.1 (Ubuntu Natty) | Undecided | Invalid | ||
937869 | MySQL security update tracking bug | mysql-dfsg-5.1 (Ubuntu Oneiric) | Undecided | Invalid | ||
937869 | MySQL security update tracking bug | mysql-5.1 (Ubuntu Lucid) | Undecided | Invalid | ||
937869 | MySQL security update tracking bug | mysql-dfsg-5.1 (Ubuntu Lucid) | Undecided | Fix Released | ||
937869 | MySQL security update tracking bug | mysql-dfsg-5.0 (Ubuntu) | Undecided | Fix Released | ||
937869 | MySQL security update tracking bug | mysql-dfsg-5.0 (Ubuntu Lucid) | Undecided | Invalid | ||
937869 | MySQL security update tracking bug | mysql-dfsg-5.0 (Ubuntu Maverick) | Undecided | Invalid | ||
937869 | MySQL security update tracking bug | mysql-dfsg-5.0 (Ubuntu Natty) | Undecided | Invalid | ||
937869 | MySQL security update tracking bug | mysql-dfsg-5.0 (Ubuntu Oneiric) | Undecided | Invalid | ||
937869 | MySQL security update tracking bug | mysql-5.1 (Ubuntu Hardy) | Undecided | Invalid | ||
937869 | MySQL security update tracking bug | mysql-dfsg-5.0 (Ubuntu Hardy) | Undecided | Fix Released | ||
937869 | MySQL security update tracking bug | mysql-dfsg-5.1 (Ubuntu Hardy) | Undecided | Invalid |
See the
CVE page on Mitre.org
for more details.