First published: Sat Oct 16 2004(Updated: )
Buffer overflow in the mysql_real_connect function in MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows remote DNS servers to cause a denial of service and possibly execute arbitrary code via a DNS response with a large address length (h_length).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MySQL | >=3.20<3.23.49 | |
MySQL | >=4.0.0<4.0.21 | |
Debian Linux | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0836 has a high severity level due to its potential for remote code execution and denial of service.
To mitigate CVE-2004-0836, upgrade MySQL to version 4.0.21 or later, or 3.23.49 or later for affected releases.
CVE-2004-0836 affects MySQL versions prior to 4.0.21 and 3.x versions prior to 3.23.49, along with certain Debian 3.0 installations.
CVE-2004-0836 is a buffer overflow vulnerability that allows remote DNS servers to exploit MySQL servers.
Yes, CVE-2004-0836 can potentially lead to data loss through denial of service or arbitrary code execution.