FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2004-0837

This CVE name corresponds to:

Entered Topic
2004-12-16 mysql -- ALTER MERGE denial of service vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2004-0837
Phase Assigned(20040908)

Description

MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows attackers to cause a denial of service (crash or hang) via multiple threads that simultaneously alter MERGE table UNIONs.

References

Source Reference
CONECTIVA CLA-2004:892
DEBIAN DSA-562
GENTOO GLSA-200410-22
MISC http://bugs.mysql.com/2408
MISC http://lists.mysql.com/internals/16168
MISC http://lists.mysql.com/internals/16173
MISC http://lists.mysql.com/internals/16174
MISC http://mysql.bkbits.net:8080/mysql-3.23/diffs/myisammrg/myrg_open.c@1.15
REDHAT RHSA-2004:597
REDHAT RHSA-2004:611
SUNALERT 101864
TRUSTIX 2004-0054
BUGTRAQ 20041125 [USN-32-1] mysql vulnerabilities
CIAC P-018
BID 11357
SECTRACK 1011606
SECUNIA 12783
XF mysql-union-dos(17667)