CVE-2003-0073: Medium severity ORACLE MySQL vulnerability
Published Feb 19, 2003
·Updated
Double-free vulnerability in mysqld for MySQL before 3.23.55 allows attackers with MySQL access to cause a denial of service (crash) via mysqlchangeuser.
Affected Software
8 affected components
ORACLE MySQL=3.23.31
ORACLE MySQL=3.23.36
ORACLE MySQL=3.23.41
ORACLE MySQL=3.23.47
ORACLE MySQL=3.23.52
ORACLE MySQL=3.23.53
ORACLE MySQL=3.23.54
ORACLE MySQL=3.23.54a
Remediation
Patch Available
Event History
Feb 19, 2003
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2003-0073?
CVE-2003-0073 has a severity rating that indicates it can cause a denial of service.
2
How do I fix CVE-2003-0073?
To fix CVE-2003-0073, upgrade MySQL to version 3.23.55 or later.
3
Which versions of MySQL are affected by CVE-2003-0073?
CVE-2003-0073 affects MySQL versions 3.23.31 through 3.23.54a.
4
What kind of attack does CVE-2003-0073 facilitate?
CVE-2003-0073 facilitates a denial of service attack through a double-free vulnerability.
5
Who is vulnerable to CVE-2003-0073?
Users with MySQL access to affected versions of MySQL are vulnerable to CVE-2003-0073.