ZDI-CAN-13864: Oracle MySQL Cluster Management API Stack-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle MySQL Cluster. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Management API. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the service account.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-13864?
ZDI-CAN-13864 is considered critical due to its potential for remote code execution.
How do I fix ZDI-CAN-13864?
To mitigate ZDI-CAN-13864, users should update to the latest version of Oracle MySQL Cluster where the vulnerability is patched.
Can ZDI-CAN-13864 be exploited without authentication?
Yes, ZDI-CAN-13864 can be exploited without requiring any authentication.
What software is affected by ZDI-CAN-13864?
ZDI-CAN-13864 specifically affects Oracle MySQL Cluster installations.
What type of vulnerability is ZDI-CAN-13864?
ZDI-CAN-13864 is a remote code execution vulnerability within the Management API of Oracle MySQL Cluster.