First published: Sun Dec 05 2004(Updated: )
MySQL before 4.0.20 allows remote attackers to cause a denial of service (application crash) via a MATCH AGAINST query with an opening double quote but no closing double quote.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MySQL | =4.0.0 | |
MySQL | =4.0.1 | |
MySQL | =4.0.2 | |
MySQL | =4.0.3 | |
MySQL | =4.0.4 | |
MySQL | =4.0.5 | |
MySQL | =4.0.5a | |
MySQL | =4.0.6 | |
MySQL | =4.0.7 | |
MySQL | =4.0.7-gamma | |
MySQL | =4.0.8 | |
MySQL | =4.0.8-gamma | |
MySQL | =4.0.9 | |
MySQL | =4.0.9-gamma | |
MySQL | =4.0.10 | |
MySQL | =4.0.11 | |
MySQL | =4.0.11-gamma | |
MySQL | =4.0.12 | |
MySQL | =4.0.13 | |
MySQL | =4.0.14 | |
MySQL | =4.0.15 | |
MySQL | =4.0.18 | |
MySQL | =4.0.20 | |
SUSE Linux | =8.0 | |
SUSE Linux | =8.1 | |
SUSE Linux | =8.2 | |
SUSE Linux | =9.0 | |
SUSE Linux | =9.0 | |
SUSE Linux | =9.1 | |
SUSE Linux | =9.2 | |
Ubuntu | =4.1 | |
Ubuntu | =4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0956 is categorized as a denial of service vulnerability that can cause application crashes.
To mitigate CVE-2004-0956, users should upgrade to MySQL version 4.0.21 or later, which addresses this issue.
CVE-2004-0956 affects MySQL versions prior to 4.0.20, including versions 4.0.0 through 4.0.20.
Yes, CVE-2004-0956 can be exploited by remote attackers through specifically crafted MATCH AGAINST queries.
Applications that utilize vulnerable versions of MySQL for database management may experience denial of service due to CVE-2004-0956.