MySQL “filesort()” Routine Single Row Subselect Query Denial of Service

A vulnerability has been identified in MySQL, which could be exploited by attackers to cause a denial of service. This issue is due to an error in the “filesort()” [filesort.cc] routine when processing a single-row subselect query sorted via the “ORDER BY” clause, which could be exploited by malicious users to crash an affected database by executing a specially crafted SQL query.

Affected Products:
MySQL versions prior to 5.0.37

Solution:
Upgrade to MySQL version 5.0.37 :
http://dev.mysql.com/downloads/

Posted March 12, 2007 | Filed under DBA News, MySQL [permalink]

News Categories

Tutorials and Docs

Sponsors

Syndicate DBA Place

Search

Archives

March 2007
M T W T F S S
« Feb   Jul »
 1234
567891011
12131415161718
19202122232425
262728293031  

Sponsors

20 queries. 0.188 seconds