First published: Thu Jul 08 2004(Updated: )
The check_scramble_323 function in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to bypass authentication via a zero-length scrambled string.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MySQL Server | =4.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0627 is considered to have a high severity rating due to the potential for remote unauthorized access.
To fix CVE-2004-0627, upgrade MySQL to version 4.1.3 or later.
CVE-2004-0627 affects MySQL versions 4.1.0 through 4.1.2 and 5.0.
CVE-2004-0627 allows remote attackers to bypass authentication, potentially compromising database security.
Yes, there are known exploits that leverage this vulnerability to gain unauthorized access to MySQL databases.