// For flags

CVE-2010-3835

MySQL: crash with user variables, assignments, joins... (MySQL Bug #55564)

Severity Score

4.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

MySQL 5.1 before 5.1.51 and 5.5 before 5.5.6 allows remote authenticated users to cause a denial of service (mysqld server crash) by performing a user-variable assignment in a logical expression that is calculated and stored in a temporary table for GROUP BY, then causing the expression value to be used after the table is created, which causes the expression to be re-evaluated instead of accessing its value from the table.

MySQL versiones 5.1 anteriores a 5.1.51 y versiones 5.5 anteriores a 5.5.6, permite a los usuarios autenticados remotos causar una denegación de servicio (bloqueo del servidor mysqld) mediante la realización de una asignación de variable de usuario en una expresión lógica que se calcula y almacena en una tabla temporal para GROUP BY y, entonces causar que sea usado el valor de la expresión después de crear la tabla, lo que causa que la expresión se vuelva a evaluar en lugar de tener acceso a su valor desde la tabla.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2010-10-07 CVE Reserved
  • 2010-11-10 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-10-19 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-189: Numeric Errors
CAPEC
References (22)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.1.5
Search vendor "Mysql" for product "Mysql" and version "5.1.5"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.1.23
Search vendor "Mysql" for product "Mysql" and version "5.1.23"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.1.31
Search vendor "Mysql" for product "Mysql" and version "5.1.31"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.1.32
Search vendor "Mysql" for product "Mysql" and version "5.1.32"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.1.34
Search vendor "Mysql" for product "Mysql" and version "5.1.34"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.1.37
Search vendor "Mysql" for product "Mysql" and version "5.1.37"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1
Search vendor "Oracle" for product "Mysql" and version "5.1"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.1
Search vendor "Oracle" for product "Mysql" and version "5.1.1"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.2
Search vendor "Oracle" for product "Mysql" and version "5.1.2"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.3
Search vendor "Oracle" for product "Mysql" and version "5.1.3"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.4
Search vendor "Oracle" for product "Mysql" and version "5.1.4"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.6
Search vendor "Oracle" for product "Mysql" and version "5.1.6"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.7
Search vendor "Oracle" for product "Mysql" and version "5.1.7"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.8
Search vendor "Oracle" for product "Mysql" and version "5.1.8"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.9
Search vendor "Oracle" for product "Mysql" and version "5.1.9"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.10
Search vendor "Oracle" for product "Mysql" and version "5.1.10"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.11
Search vendor "Oracle" for product "Mysql" and version "5.1.11"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.12
Search vendor "Oracle" for product "Mysql" and version "5.1.12"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.13
Search vendor "Oracle" for product "Mysql" and version "5.1.13"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.14
Search vendor "Oracle" for product "Mysql" and version "5.1.14"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.15
Search vendor "Oracle" for product "Mysql" and version "5.1.15"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.16
Search vendor "Oracle" for product "Mysql" and version "5.1.16"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.17
Search vendor "Oracle" for product "Mysql" and version "5.1.17"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.18
Search vendor "Oracle" for product "Mysql" and version "5.1.18"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.19
Search vendor "Oracle" for product "Mysql" and version "5.1.19"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.20
Search vendor "Oracle" for product "Mysql" and version "5.1.20"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.21
Search vendor "Oracle" for product "Mysql" and version "5.1.21"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.22
Search vendor "Oracle" for product "Mysql" and version "5.1.22"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.23
Search vendor "Oracle" for product "Mysql" and version "5.1.23"
a
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.24
Search vendor "Oracle" for product "Mysql" and version "5.1.24"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.25
Search vendor "Oracle" for product "Mysql" and version "5.1.25"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.26
Search vendor "Oracle" for product "Mysql" and version "5.1.26"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.27
Search vendor "Oracle" for product "Mysql" and version "5.1.27"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.28
Search vendor "Oracle" for product "Mysql" and version "5.1.28"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.29
Search vendor "Oracle" for product "Mysql" and version "5.1.29"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.30
Search vendor "Oracle" for product "Mysql" and version "5.1.30"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.31
Search vendor "Oracle" for product "Mysql" and version "5.1.31"
sp1
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.33
Search vendor "Oracle" for product "Mysql" and version "5.1.33"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.34
Search vendor "Oracle" for product "Mysql" and version "5.1.34"
sp1
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.35
Search vendor "Oracle" for product "Mysql" and version "5.1.35"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.36
Search vendor "Oracle" for product "Mysql" and version "5.1.36"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.37
Search vendor "Oracle" for product "Mysql" and version "5.1.37"
sp1
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.38
Search vendor "Oracle" for product "Mysql" and version "5.1.38"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.39
Search vendor "Oracle" for product "Mysql" and version "5.1.39"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.40
Search vendor "Oracle" for product "Mysql" and version "5.1.40"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.40
Search vendor "Oracle" for product "Mysql" and version "5.1.40"
sp1
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.41
Search vendor "Oracle" for product "Mysql" and version "5.1.41"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.42
Search vendor "Oracle" for product "Mysql" and version "5.1.42"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.43
Search vendor "Oracle" for product "Mysql" and version "5.1.43"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.43
Search vendor "Oracle" for product "Mysql" and version "5.1.43"
sp1
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.44
Search vendor "Oracle" for product "Mysql" and version "5.1.44"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.45
Search vendor "Oracle" for product "Mysql" and version "5.1.45"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.46
Search vendor "Oracle" for product "Mysql" and version "5.1.46"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.46
Search vendor "Oracle" for product "Mysql" and version "5.1.46"
sp1
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.47
Search vendor "Oracle" for product "Mysql" and version "5.1.47"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.48
Search vendor "Oracle" for product "Mysql" and version "5.1.48"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.49
Search vendor "Oracle" for product "Mysql" and version "5.1.49"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.49
Search vendor "Oracle" for product "Mysql" and version "5.1.49"
sp1
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.1.50
Search vendor "Oracle" for product "Mysql" and version "5.1.50"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.5.0
Search vendor "Oracle" for product "Mysql" and version "5.5.0"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.5.1
Search vendor "Oracle" for product "Mysql" and version "5.5.1"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.5.2
Search vendor "Oracle" for product "Mysql" and version "5.5.2"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.5.3
Search vendor "Oracle" for product "Mysql" and version "5.5.3"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.5.4
Search vendor "Oracle" for product "Mysql" and version "5.5.4"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.5.5
Search vendor "Oracle" for product "Mysql" and version "5.5.5"
-
Affected