CVE-2010-3678: Medium severity MySQL mysql vulnerability

Published Aug 28, 2010
·
Updated

A denial of service flaw was found in the way MySQL processed SQL queries containing IN or CASE statements, when NULL argument was provided as one of the arguments to the query. A remote MySQL user could use this flaw to cause myqld daemon crash (dereference a NULL pointer).

References: [1] http://secunia.com/advisories/41048/ [2] http://dev.mysql.com/doc/refman/5.1/en/news-5-1-49.html

Upstream bug report: [3] http://bugs.mysql.com/bug.php?id=54477

Upstream changeset: [4] http://lists.mysql.com/commits/111814

Other sources

Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (crash) via (1) IN or (2) CASE operations with NULL arguments that are explicitly specified or indirectly provided by the WITH ROLLUP modifier.

Affected Software

56 affected components
MySQL mysql=5.1.5
MySQL mysql=5.1.23
MySQL mysql=5.1.31
MySQL mysql=5.1.32
MySQL mysql=5.1.34
MySQL mysql=5.1.37
Oracle MySQL=5.1
Oracle MySQL=5.1.1
Oracle MySQL=5.1.2
Oracle MySQL=5.1.3
Oracle MySQL=5.1.4
Oracle MySQL=5.1.6
Oracle MySQL=5.1.7
Oracle MySQL=5.1.8
Oracle MySQL=5.1.9
Oracle MySQL=5.1.10
Oracle MySQL=5.1.11
Oracle MySQL=5.1.12
Oracle MySQL=5.1.13
Oracle MySQL=5.1.14
Oracle MySQL=5.1.15
Oracle MySQL=5.1.16
Oracle MySQL=5.1.17
Oracle MySQL=5.1.18
Oracle MySQL=5.1.19
Oracle MySQL=5.1.20
Oracle MySQL=5.1.21
Oracle MySQL=5.1.22
Oracle MySQL=5.1.23-a
Oracle MySQL=5.1.24
Oracle MySQL=5.1.25
Oracle MySQL=5.1.26
Oracle MySQL=5.1.27
Oracle MySQL=5.1.28
Oracle MySQL=5.1.29
Oracle MySQL=5.1.30
Oracle MySQL=5.1.31-sp1
Oracle MySQL=5.1.33
Oracle MySQL=5.1.34-sp1
Oracle MySQL=5.1.35
Oracle MySQL=5.1.36
Oracle MySQL=5.1.37-sp1
Oracle MySQL=5.1.38
Oracle MySQL=5.1.39
Oracle MySQL=5.1.40
Oracle MySQL=5.1.40-sp1
Oracle MySQL=5.1.41
Oracle MySQL=5.1.42
Oracle MySQL=5.1.43
Oracle MySQL=5.1.43-sp1
Oracle MySQL=5.1.44
Oracle MySQL=5.1.45
Oracle MySQL=5.1.46
Oracle MySQL=5.1.46-sp1
Oracle MySQL=5.1.47
Oracle MySQL=5.1.48

Event History

Aug 28, 2010
Data Sourced
11:28 AM
DescriptionSeverityAffected Software
Jan 11, 2011
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2010-3678?

CVE-2010-3678 is classified as a denial of service vulnerability that can cause the MySQL daemon to crash.

2

How do I fix CVE-2010-3678?

To fix CVE-2010-3678, you should upgrade to a patched version of MySQL that is not affected by this vulnerability.

3

What versions of MySQL are affected by CVE-2010-3678?

CVE-2010-3678 affects multiple versions of MySQL 5.1, including versions 5.1.5 through 5.1.48.

4

Can CVE-2010-3678 be exploited remotely?

Yes, CVE-2010-3678 can be exploited remotely by a MySQL user through maliciously crafted SQL queries.

5

What type of attacks does CVE-2010-3678 enable?

CVE-2010-3678 enables attacks that result in denial of service, leading to application downtime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203