FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2004-0836

This CVE name corresponds to:

Entered Topic
2004-12-16 mysql -- mysql_real_connect buffer overflow vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2004-0836
Phase Assigned(20040908)

Description

Buffer overflow in the mysql_real_connect function in MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows remote DNS servers to cause a denial of service and possibly execute arbitrary code via a DNS response with a large address length (h_length).

References

Source Reference
CONECTIVA CLA-2004:892
DEBIAN DSA-562
GENTOO GLSA-200410-22
MISC http://bugs.mysql.com/bug.php?id=4017
MISC http://lists.mysql.com/internals/14726
REDHAT RHSA-2004:597
REDHAT RHSA-2004:611
TRUSTIX 2004-0054
BUGTRAQ 20041125 [USN-32-1] mysql vulnerabilities
CIAC P-018
BID 10981
SECUNIA 12305
XF mysql-realconnect-bo(17047)