First published: Fri Dec 31 2004(Updated: )
MySQL MaxDB before 7.5.00.18 allows remote attackers to cause a denial of service (crash) via an HTTP request to webdbm with high ASCII values in the Server field, which triggers an assert error in the IsAscii7 function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MySQL MaxDB | =7.5.00.15 | |
MySQL MaxDB | =7.5.00.12 | |
MySQL MaxDB | =7.5.00.16 | |
MySQL MaxDB | =7.5.00.14 | |
MySQL MaxDB | =7.5.00.11 | |
MySQL MaxDB | =7.5.00.08 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0931 is classified as a denial of service vulnerability which can lead to crashes of the MySQL MaxDB server.
To mitigate CVE-2004-0931, upgrade to MySQL MaxDB version 7.5.00.18 or later.
CVE-2004-0931 affects MySQL MaxDB versions 7.5.00.11, 7.5.00.12, 7.5.00.14, 7.5.00.15, and 7.5.00.16.
CVE-2004-0931 is associated with remote denial of service attacks triggered by malformed HTTP requests.
Yes, using any version of MySQL MaxDB prior to 7.5.00.18 exposes your system to risks from CVE-2004-0931.