MySQL 5.0 before 5.0.66, 5.1 before 5.1.26, and 6.0 before 6.0.6 does not properly handle a b'' (b single-quote single-quote) token, aka an empty bit-string literal, which allows remote attackers to cause a denial of service (daemon crash) by using this token in a SQL statement.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2008-09-11 01:13
Updated : 2025-04-09 00:30
NVD link : CVE-2008-3963
Mitre link : CVE-2008-3963
CVE.ORG link : CVE-2008-3963
JSON object : View
Products Affected
oracle
- mysql
mysql
- mysql
CWE
CWE-134
Use of Externally-Controlled Format String