CVE-2009-2446: High severity mysql vulnerability
Multiple format string vulnerabilities in the dispatchcommand function in libmysqld/sqlparse.cc in mysqld in MySQL 4.0.0 through 5.0.83 allow remote authenticated users to cause a denial of service (daemon crash) and possibly have unspecified other impact via format string specifiers in a database name in a (1) COMCREATEDB or (2) COMDROPDB request. NOTE: some of these details are obtained from third party information.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2446?
CVE-2009-2446 has a severity level that allows remote authenticated users to potentially cause a denial of service by exploiting format string vulnerabilities.
How do I fix CVE-2009-2446?
To fix CVE-2009-2446, update MySQL to a patched version that addresses the format string vulnerabilities.
Which versions of MySQL are affected by CVE-2009-2446?
CVE-2009-2446 affects MySQL versions from 4.0.0 to 5.0.83.
What type of vulnerability is CVE-2009-2446?
CVE-2009-2446 is classified as a multiple format string vulnerability.
Can CVE-2009-2446 lead to unauthorized access?
While CVE-2009-2446 primarily poses a denial of service risk, it may lead to unspecified other impacts as well.