CVE-2004-1169: Medium severity mysql maxdb vulnerability
Published Dec 10, 2004
·Updated
MaxDB WebTools 7.5.00.18 and earlier allows remote attackers to cause a denial of service (application crash) via an HTTP GET request for a file that does not exist, followed by two carriage returns, which causes a NULL dereference.
Affected Software
7 affected components
MySQL MaxDB=7.5.00.18
MySQL MaxDB=7.5.00.15
MySQL MaxDB=7.5.00.12
MySQL MaxDB=7.5.00.16
MySQL MaxDB=7.5.00.14
MySQL MaxDB=7.5.00.11
MySQL MaxDB=7.5.00.08
Event History
Dec 10, 2004
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1169?
CVE-2004-1169 has a severity rating that indicates it is a denial-of-service vulnerability.
2
How do I fix CVE-2004-1169?
To fix CVE-2004-1169, it is recommended to upgrade to a later, patched version of MaxDB that addresses this vulnerability.
3
What versions of MySQL MaxDB are affected by CVE-2004-1169?
MySQL MaxDB versions 7.5.00.08 to 7.5.00.18 are known to be affected by CVE-2004-1169.
4
Can CVE-2004-1169 be exploited remotely?
Yes, CVE-2004-1169 can be exploited remotely through a crafted HTTP GET request.
5
What type of impact does CVE-2004-1169 have on MySQL MaxDB?
CVE-2004-1169 can cause a crash in the MaxDB application, leading to a denial of service.