CVE-2000-0148: High severity ORACLE MySQL vulnerability
MySQL 3.22 allows remote attackers to bypass password authentication and access a database via a short check string.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
mysql/3.22from your environment.Uninstall or take offline any MySQL 3.22 installations; this version is vulnerable to password bypass and no fixed version is specified in the provided material.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0148?
CVE-2000-0148 is considered a critical vulnerability allowing unauthorized remote access to MySQL databases.
How do I fix CVE-2000-0148?
To fix CVE-2000-0148, upgrade MySQL to a version that is not affected, such as versions later than 3.23.10.
Which MySQL versions are affected by CVE-2000-0148?
CVE-2000-0148 affects MySQL versions 3.22.26, 3.22.27, 3.22.29, 3.22.30, 3.23.8, 3.23.9, and 3.23.10.
What impact does CVE-2000-0148 have on security?
CVE-2000-0148 allows remote attackers to bypass password authentication, compromising database integrity and confidentiality.
How was CVE-2000-0148 discovered?
CVE-2000-0148 was identified through vulnerability research and reported in security forums, highlighting its potential to allow unauthorized access.