REDHAT-BUG-628040: Medium severity MySQL mysql vulnerability
A denial of service flaw was found in the way MySQL processed joins queries, which involved a table with unique SET column. A remote MySQL user could use this flaw to cause mysqld daemon crash.
References: [1] http://secunia.com/advisories/41048/ [2] http://dev.mysql.com/doc/refman/5.1/en/news-5-1-49.html
Upstream bug report: [3] http://bugs.mysql.com/bug.php?id=54575
Note: This issue only causes a temporary denial of service, as the mysql daemon shipped with Red Hat Enterprise Linux 5 will be automatically restarted after the crash.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-628040?
The severity of REDHAT-BUG-628040 is classified as a denial of service vulnerability.
How do I fix REDHAT-BUG-628040?
To fix REDHAT-BUG-628040, update your MySQL version to a patched release that addresses this vulnerability.
Who is affected by REDHAT-BUG-628040?
Any remote MySQL user operating with a version that allows unique SET column processing is affected by REDHAT-BUG-628040.
What type of attack can exploit REDHAT-BUG-628040?
REDHAT-BUG-628040 can be exploited via crafted join queries, leading to a crash of the mysqld daemon.
Is REDHAT-BUG-628040 specific to any MySQL version?
Yes, REDHAT-BUG-628040 specifically affects certain versions of MySQL that handle joins improperly.