Bug 190870

Summary: CVE-2006-1518 Mysql buffer overflow
Product: [Fedora] Fedora Reporter: Josh Bressers <bressers>
Component: mysqlAssignee: Tom Lane <tgl>
Status: CLOSED RAWHIDE QA Contact: David Lawrence <dkl>
Severity: high Docs Contact:
Priority: medium    
Version: 5CC: byte, hhorak, starback
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: impact=important,source=vendorsec,public=20060502,reported=20060503
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2006-05-18 02:02:47 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Josh Bressers 2006-05-05 19:45:04 UTC
Buffer overflow in the open_table function in sql_base.cc in MySQL 5.0.x up to
5.0.20 might allow remote attackers to execute arbitrary code via crafted
COM_TABLE_DUMP packets with invalid length values.

http://www.wisec.it/vulns.php?page=8

Comment 1 starback 2006-05-08 07:40:04 UTC
Also for 4.1.x up to 4.1.18, so FC 4 is also affected.

Comment 2 Tom Lane 2006-05-18 02:02:47 UTC
5.0.21 is pushed into FC5, and 4.1.19 into FC4.