FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2007-3780

This CVE name corresponds to:

Entered Topic
2009-01-11 mysql -- remote dos via malformed password packet

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2007-3780
Phase Assigned(20070715)

Description

MySQL Community Server before 5.0.45 allows remote attackers to cause a denial of service (daemon crash) via a malformed password packet in the connection protocol.

References

Source Reference
BUGTRAQ 20070717 rPSA-2007-0143-1 mysql mysql-bench mysql-server
MLIST [announce] 20070712 MySQL Community Server 5.0.45 has been released!
MISC http://bugs.mysql.com/bug.php?id=28984
CONFIRM https://issues.rpath.com/browse/RPL-1536
CONFIRM http://dev.mysql.com/doc/refman/5.0/en/releasenotes-cs-5-0-45.html
CONFIRM http://dev.mysql.com/doc/refman/4.1/en/news-4-1-24.html
DEBIAN DSA-1413
GENTOO GLSA-200708-10
MANDRIVA MDKSA-2007:177
REDHAT RHSA-2007:0894
REDHAT RHSA-2007:0875
SUSE SUSE-SR:2007:019
UBUNTU USN-528-1
BID 25017
OSVDB 36732
OVAL oval:org.mitre.oval:def:11058
VUPEN ADV-2008-1000
SECTRACK 1018629
SECUNIA 26073
SECUNIA 26498
SECUNIA 26710
SECUNIA 25301
SECUNIA 26987
SECUNIA 26621
SECUNIA 27155
SECUNIA 26430
SECUNIA 27823