Total vulnerabilities in the database
Oracle MySQL 5.1.67 and earlier and 5.5.29 and earlier, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a denial of service (mysqld crash) via a SELECT command with an UpdateXML command containing XML with a large number of unique, nested elements.
Software | From | Fixed in |
---|---|---|
oracle / mysql | 5.1.0 | 5.1.67.x |
oracle / mysql | 5.5.0 | 5.5.29.x |
mariadb / mariadb | 5.5.0 | 5.5.30 |
mariadb / mariadb | 10.0.0 | 10.0.2 |
redhat / enterprise_linux_server_aus | 6.4 | 6.4.x |
redhat / enterprise_linux_desktop | 6.0 | 6.0.x |
redhat / enterprise_linux_server | 6.0 | 6.0.x |
redhat / enterprise_linux_workstation | 6.0 | 6.0.x |
redhat / enterprise_linux_eus | 6.4 | 6.4.x |