CVE-2010-1849

Impact:
Low
Public Date:
2010-05-13
Bugzilla:
592086: CVE-2010-1849 mysql: over-sized packet denial of service vulnerability

The MITRE CVE dictionary describes this issue as:

The my_net_skip_rest function in sql/net_serv.cc in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by sending a large number of packets that exceed the maximum length.

Find out more about CVE-2010-1849 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

This issue was fixed in mysql packages shipped with Red Hat Enterprise Linux 5 via RHSA-2012:0127. The mysql packages in Red Hat Enterprise Linux 6 include this fix since the initial release of the product.

CVSS v2 metrics

Base Score 2.6
Base Metrics AV:N/AC:H/Au:N/C:N/I:N/A:P
Access Vector Network
Access Complexity High
Authentication None
Confidentiality Impact None
Integrity Impact None
Availability Impact Partial

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 5 (mysql) RHSA-2012:0127 2012-02-13

Affected Packages State

Platform Package State
Red Hat Enterprise Linux 6 mysql Will not fix
Red Hat Enterprise Linux 4 mysql Will not fix
Red Hat Enterprise Linux 3 mysql Not affected

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.