Hide Forgot
A denial of service flaw was found in the way MySQL processed HANDLER READ NEXT statements after deleting a record. A remote, authenticated MySQL user could use this flaw to cause mysqld daemon abort (assertion failure). References: http://dev.mysql.com/doc/refman/5.5/en/news-5-5-22.html http://dev.mysql.com/doc/refman/5.1/en/news-5-1-62.html https://bugs.gentoo.org/show_bug.cgi?id=411503 http://eromang.zataz.com/2012/04/10/oracle-mysql-innodb-bugs-13510739-and-63775-dos-demo/ http://www.openwall.com/lists/oss-security/2012/04/13/7 Upstream commit: http://bazaar.launchpad.net/~mysql/mysql-server/5.1/revision/3560.8.4 http://bazaar.launchpad.net/~mysql/mysql-server/5.5/revision/3097.15.15
Created mysql tracking bugs for this issue Affects: fedora-all [bug 812436]
Added CVE as per http://www.openwall.com/lists/oss-security/2012/04/13/7
This issue has been addressed in following products: Red Hat Enterprise Linux 6 Via RHSA-2012:0874 https://rhn.redhat.com/errata/RHSA-2012-0874.html
Statement: This issue did not affect the versions of mysql as shipped with Red Hat Enterprise Linux 5.