Multiple buffer overflows in the web tool for MySQL MaxDB before 7.5.00.26 allows remote attackers to execute arbitrary code via (1) an HTTP GET request with a long file parameter after a percent ("%") sign or (2) a long Lock-Token string to the WebDAV functionality, which is not properly handled by the getLockTokenHeader function in WDVHandler_CommonUtils.c.
Software | From | Fixed in |
---|---|---|
mysql / maxdb | 7.5.00 | 7.5.00.x |
mysql / maxdb | 7.5.00.08 | 7.5.00.08.x |
mysql / maxdb | 7.5.00.11 | 7.5.00.11.x |
mysql / maxdb | 7.5.00.12 | 7.5.00.12.x |
mysql / maxdb | 7.5.00.14 | 7.5.00.14.x |
mysql / maxdb | 7.5.00.15 | 7.5.00.15.x |
mysql / maxdb | 7.5.00.16 | 7.5.00.16.x |
mysql / maxdb | 7.5.00.18 | 7.5.00.18.x |
mysql / maxdb | 7.5.00.19 | 7.5.00.19.x |
mysql / maxdb | 7.5.00.23 | 7.5.00.23.x |