First published: Sat Oct 16 2004(Updated: )
MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows attackers to cause a denial of service (crash or hang) via multiple threads that simultaneously alter MERGE table UNIONs.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MySQL (MySQL-common) | =4.1.0 | |
Oracle MySQL | >=3.20<3.23.49 | |
Oracle MySQL | >=4.0.0<4.0.21 | |
Debian | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0837 has a severity rating that warrants concern due to its potential for causing a denial of service.
To fix CVE-2004-0837, upgrade to MySQL version 4.0.21 or later, or 3.23.49 or later.
CVE-2004-0837 affects MySQL versions prior to 4.0.21 and 3.23.49.
CVE-2004-0837 can cause your MySQL database to crash or hang when multiple threads modify MERGE table UNIONs.
There are no formally documented workarounds for CVE-2004-0837 other than upgrading to a patched version.