CVE-2004-0836: Buffer Overflow
Buffer overflow in the mysqlrealconnect function in MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows remote DNS servers to cause a denial of service and possibly execute arbitrary code via a DNS response with a large address length (hlength).
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0836?
CVE-2004-0836 has a high severity level due to its potential for remote code execution and denial of service.
How do I fix CVE-2004-0836?
To mitigate CVE-2004-0836, upgrade MySQL to version 4.0.21 or later, or 3.23.49 or later for affected releases.
What software is affected by CVE-2004-0836?
CVE-2004-0836 affects MySQL versions prior to 4.0.21 and 3.x versions prior to 3.23.49, along with certain Debian 3.0 installations.
What is the nature of the vulnerability in CVE-2004-0836?
CVE-2004-0836 is a buffer overflow vulnerability that allows remote DNS servers to exploit MySQL servers.
Can CVE-2004-0836 lead to data loss?
Yes, CVE-2004-0836 can potentially lead to data loss through denial of service or arbitrary code execution.