First published: Thu Mar 05 2009(Updated: )
sql/item_xmlfunc.cc in MySQL 5.1 before 5.1.32 and 6.0 before 6.0.10 allows remote authenticated users to cause a denial of service (crash) via "an XPath expression employing a scalar expression as a FilterExpr with ExtractValue() or UpdateXML()," which triggers an assertion failure.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MySQL (MySQL-common) | =5.1.23 | |
MySQL (MySQL-common) | =6.0.9 | |
MySQL (MySQL-common) | <=5.1.32-bzr | |
MySQL (MySQL-common) | =5.1.31 | |
MySQL (MySQL-common) | =6.0.10-bzr | |
Oracle MySQL | =6.0.0 | |
Oracle MySQL | =6.0.1 | |
Oracle MySQL | =6.0.2 | |
Oracle MySQL | =6.0.3 | |
Oracle MySQL | =6.0.4 | |
Oracle MySQL | =5.1 | |
Oracle MySQL | =5.1.1 | |
Oracle MySQL | =5.1.2 | |
Oracle MySQL | =5.1.3 | |
Oracle MySQL | =5.1.10 | |
Oracle MySQL | =5.1.11 | |
Oracle MySQL | =5.1.12 | |
Oracle MySQL | =5.1.13 | |
Oracle MySQL | =5.1.14 | |
Oracle MySQL | =5.1.15 | |
Oracle MySQL | =5.1.16 | |
Oracle MySQL | =5.1.17 | |
Oracle MySQL | =5.1.18 | |
Oracle MySQL | =5.1.19 | |
Oracle MySQL | =5.1.20 | |
Oracle MySQL | =5.1.21 | |
Oracle MySQL | =5.1.22 | |
Oracle MySQL | =5.1.24 | |
Oracle MySQL | =5.1.25 | |
Oracle MySQL | =5.1.26 | |
Oracle MySQL | =5.1.27 | |
Oracle MySQL | =5.1.28 | |
Oracle MySQL | =5.1.29 | |
Oracle MySQL | =5.1.30 | |
Oracle MySQL | =5.1.23-a | |
Oracle MySQL | =5.1.31-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0819 has been classified as a denial of service vulnerability that can lead to application crashes.
To fix CVE-2009-0819, upgrade MySQL to version 5.1.32 or later for 5.1 series, and to version 6.0.10 or later for 6.0 series.
CVE-2009-0819 affects MySQL versions 5.1.23 through 5.1.31 and 6.0.0 through 6.0.9.
CVE-2009-0819 allows remote authenticated users to exploit the vulnerability to cause a denial of service by crashing the MySQL server.
Yes, CVE-2009-0819 can be exploited remotely by authenticated users of the MySQL server.