First published: Mon Feb 27 2006(Updated: )
MySQL 5.0.18 and earlier allows local users to bypass logging mechanisms via SQL queries that contain the NULL character, which are not properly handled by the mysql_real_query function. NOTE: this issue was originally reported for the mysql_query function, but the vendor states that since mysql_query expects a null character, this is not an issue for mysql_query.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
MySQL MySQL | =4.1.0 | |
MySQL MySQL | =4.1.3 | |
MySQL MySQL | =4.1.8 | |
MySQL MySQL | =4.1.10 | |
MySQL MySQL | =4.1.12 | |
MySQL MySQL | =4.1.13 | |
MySQL MySQL | =4.1.14 | |
MySQL MySQL | =4.1.15 | |
MySQL MySQL | =5.0.1 | |
MySQL MySQL | =5.0.2 | |
MySQL MySQL | =5.0.4 | |
MySQL MySQL | =5.0.5 | |
MySQL MySQL | =5.0.10 | |
MySQL MySQL | =5.0.15 | |
MySQL MySQL | =5.0.16 | |
MySQL MySQL | =5.0.17 | |
Oracle MySQL | =3.23 | |
Oracle MySQL | =3.23.0-alpha | |
Oracle MySQL | =3.23.1 | |
Oracle MySQL | =3.23.2 | |
Oracle MySQL | =3.23.3 | |
Oracle MySQL | =3.23.4 | |
Oracle MySQL | =3.23.5 | |
Oracle MySQL | =3.23.6 | |
Oracle MySQL | =3.23.7 | |
Oracle MySQL | =3.23.8 | |
Oracle MySQL | =3.23.9 | |
Oracle MySQL | =3.23.10 | |
Oracle MySQL | =3.23.11 | |
Oracle MySQL | =3.23.12 | |
Oracle MySQL | =3.23.13 | |
Oracle MySQL | =3.23.14 | |
Oracle MySQL | =3.23.15 | |
Oracle MySQL | =3.23.16 | |
Oracle MySQL | =3.23.17 | |
Oracle MySQL | =3.23.18 | |
Oracle MySQL | =3.23.19 | |
Oracle MySQL | =3.23.20-beta | |
Oracle MySQL | =3.23.21 | |
Oracle MySQL | =3.23.22 | |
Oracle MySQL | =3.23.23 | |
Oracle MySQL | =3.23.24 | |
Oracle MySQL | =3.23.25 | |
Oracle MySQL | =3.23.26 | |
Oracle MySQL | =3.23.27 | |
Oracle MySQL | =3.23.28-gamma | |
Oracle MySQL | =3.23.29 | |
Oracle MySQL | =3.23.30 | |
Oracle MySQL | =3.23.31 | |
Oracle MySQL | =3.23.32 | |
Oracle MySQL | =3.23.33 | |
Oracle MySQL | =3.23.34 | |
Oracle MySQL | =3.23.35 | |
Oracle MySQL | =3.23.36 | |
Oracle MySQL | =3.23.37 | |
Oracle MySQL | =3.23.38 | |
Oracle MySQL | =3.23.39 | |
Oracle MySQL | =3.23.40 | |
Oracle MySQL | =3.23.41 | |
Oracle MySQL | =3.23.42 | |
Oracle MySQL | =3.23.43 | |
Oracle MySQL | =3.23.44 | |
Oracle MySQL | =3.23.45 | |
Oracle MySQL | =3.23.46 | |
Oracle MySQL | =3.23.47 | |
Oracle MySQL | =3.23.48 | |
Oracle MySQL | =3.23.49 | |
Oracle MySQL | =3.23.50 | |
Oracle MySQL | =3.23.51 | |
Oracle MySQL | =3.23.52 | |
Oracle MySQL | =3.23.53 | |
Oracle MySQL | =3.23.54 | |
Oracle MySQL | =3.23.55 | |
Oracle MySQL | =3.23.56 | |
Oracle MySQL | =3.23.57 | |
Oracle MySQL | =3.23.58 | |
Oracle MySQL | =3.23.59 | |
Oracle MySQL | =4.0.0 | |
Oracle MySQL | =4.0.1 | |
Oracle MySQL | =4.0.2 | |
Oracle MySQL | =4.0.3 | |
Oracle MySQL | =4.0.4 | |
Oracle MySQL | =4.0.5 | |
Oracle MySQL | =4.0.5a | |
Oracle MySQL | =4.0.6 | |
Oracle MySQL | =4.0.7 | |
Oracle MySQL | =4.0.7-gamma | |
Oracle MySQL | =4.0.8 | |
Oracle MySQL | =4.0.8-gamma | |
Oracle MySQL | =4.0.9 | |
Oracle MySQL | =4.0.9-gamma | |
Oracle MySQL | =4.0.10 | |
Oracle MySQL | =4.0.11 | |
Oracle MySQL | =4.0.11-gamma | |
Oracle MySQL | =4.0.12 | |
Oracle MySQL | =4.0.13 | |
Oracle MySQL | =4.0.14 | |
Oracle MySQL | =4.0.15 | |
Oracle MySQL | =4.0.16 | |
Oracle MySQL | =4.0.17 | |
Oracle MySQL | =4.0.18 | |
Oracle MySQL | =4.0.19 | |
Oracle MySQL | =4.0.20 | |
Oracle MySQL | =4.0.21 | |
Oracle MySQL | =4.0.23 | |
Oracle MySQL | =4.0.24 | |
Oracle MySQL | =4.0.25 | |
Oracle MySQL | =4.0.26 | |
Oracle MySQL | =4.0.27 | |
Oracle MySQL | =4.1.0-alpha | |
Oracle MySQL | =4.1.2-alpha | |
Oracle MySQL | =4.1.3-beta | |
Oracle MySQL | =4.1.4 | |
Oracle MySQL | =4.1.5 | |
Oracle MySQL | =4.1.6 | |
Oracle MySQL | =4.1.7 | |
Oracle MySQL | =4.1.9 | |
Oracle MySQL | =4.1.11 | |
Oracle MySQL | =4.1.16 | |
Oracle MySQL | =4.1.17 | |
Oracle MySQL | =4.1.18 | |
Oracle MySQL | =4.1.19 | |
Oracle MySQL | =5.0.0-alpha | |
Oracle MySQL | =5.0.3-beta | |
Oracle MySQL | =5.0.6 | |
Oracle MySQL | =5.0.7 | |
Oracle MySQL | =5.0.8 | |
Oracle MySQL | =5.0.9 | |
Oracle MySQL | =5.0.11 | |
Oracle MySQL | =5.0.12 | |
Oracle MySQL | =5.0.13 | |
Oracle MySQL | =5.0.14 | |
Oracle MySQL | =5.0.18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.