|| Hotline : 800 2378 ||  To contact CERT-MU send e-mail on --> info[at]cert-mu.gov.mu ||  To report incident e-mail on --> incident[at]cert-mu.gov.mu || To report Vulnerabilities send e-mail on --> Vulnerability[at]cert-mu.gov.mu ||
    Constituency
    Authority
    Vol. 2, Feb 2012
    Vol. 1, Oct 2011
    World CERTs
    Email Abuse
 
 
Authorized to use CERT(TM) - CERT is a mark owned by Carnegie Mellon University
 
 
 
 
 
 
 
 
 
 
 
 


   
 

CERT-MU Vulnerability Note VN-2009-7

MySQL XPath Scalar Expression Handling Denial of Service Vulnerability

Original Issue Date: March 09, 2009

Severity Rating: Medium

Systems Affected

  • MySQL 5.1.15
  • MySQL 5.1.30
  • MySQL 6.0.9

Overview

Vulnerability has been reported in MySQL which could be exploited by a remote authenticated attacker to crash an affected server, creating a denial of service condition.

Description

A denial of service vulnerability exists in MySQL caused by an assertion error when handling malformed XPath expressions. By invoking the ExtractValue() or UpdateXML() functions using a specially-crafted XPath expression containing scalar FilterExp expressions, a remote attacker could exploit this vulnerability to cause a denial of service.

Solution

Upgrade to MySQL version 5.1.32.

Disclaimer

The information provided herein is on "as is" basis, without warranty of any kind.

Vendor Information

MySQL
http://bugs.mysql.com/bug.php?id=42495

http://dev.mysql.com/doc/refman/5.1/en/news-5-1-32.html


CVE Name
CVE-2009-0819

References

ISS X-Force Database
http://xforce.iss.net/xforce/xfdb/49050


Vupen Security
http://www.vupen.com/english/advisories/2009/0594

Secunia
http://secunia.com/advisories/34115

Security Lab
http://en.securitylab.ru/nvd/369535.php

Security Database
http://www.security-database.com/detail.php?alert=CVE-2009-0819

 
 
News & Events
Safer Internet Day 2012
Computer Security Day 2011
Workshop on Cloud Security
Workshop on Mobile Security
Certificate Award Ceremony for Trainings in Information Security Management

  more...
 
Virus Alerts
RSS Feed
 
 
 

Last Updated 20-Jul-2011
Disclaimer Maintained & Hosted by NCB
This site is best viewed in 1024 x 768 resolution. Internet Explorer 6.0 +

10-Jul-2011