Buffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x, allows attackers with ALTER TABLE privileges to execute arbitrary code via a long Password field.
2003-09-22T04:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 9.0 (HIGH)
AV:N/AC:L/Au:S/C:C/I:C/A:C
8.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mysql | mysql | 4.1.0 | Yes |
Application | oracle | mysql | 3.23 | Yes |
Application | oracle | mysql | 3.23.2 | Yes |
Application | oracle | mysql | 3.23.3 | Yes |
Application | oracle | mysql | 3.23.4 | Yes |
Application | oracle | mysql | 3.23.5 | Yes |
Application | oracle | mysql | 3.23.8 | Yes |
Application | oracle | mysql | 3.23.9 | Yes |
Application | oracle | mysql | 3.23.10 | Yes |
Application | oracle | mysql | 3.23.22 | Yes |
Application | oracle | mysql | 3.23.23 | Yes |
Application | oracle | mysql | 3.23.24 | Yes |
Application | oracle | mysql | 3.23.25 | Yes |
Application | oracle | mysql | 3.23.26 | Yes |
Application | oracle | mysql | 3.23.27 | Yes |
Application | oracle | mysql | 3.23.28 | Yes |
Application | oracle | mysql | 3.23.28 | Yes |
Application | oracle | mysql | 3.23.29 | Yes |
Application | oracle | mysql | 3.23.30 | Yes |
Application | oracle | mysql | 3.23.31 | Yes |
Application | oracle | mysql | 3.23.32 | Yes |
Application | oracle | mysql | 3.23.33 | Yes |
Application | oracle | mysql | 3.23.34 | Yes |
Application | oracle | mysql | 3.23.36 | Yes |
Application | oracle | mysql | 3.23.37 | Yes |
Application | oracle | mysql | 3.23.38 | Yes |
Application | oracle | mysql | 3.23.39 | Yes |
Application | oracle | mysql | 3.23.40 | Yes |
Application | oracle | mysql | 3.23.41 | Yes |
Application | oracle | mysql | 3.23.42 | Yes |
Application | oracle | mysql | 3.23.43 | Yes |
Application | oracle | mysql | 3.23.44 | Yes |
Application | oracle | mysql | 3.23.45 | Yes |
Application | oracle | mysql | 3.23.46 | Yes |
Application | oracle | mysql | 3.23.47 | Yes |
Application | oracle | mysql | 3.23.48 | Yes |
Application | oracle | mysql | 3.23.49 | Yes |
Application | oracle | mysql | 3.23.50 | Yes |
Application | oracle | mysql | 3.23.51 | Yes |
Application | oracle | mysql | 3.23.52 | Yes |
Application | oracle | mysql | 3.23.53 | Yes |
Application | oracle | mysql | 3.23.53a | Yes |
Application | oracle | mysql | 3.23.54 | Yes |
Application | oracle | mysql | 3.23.54a | Yes |
Application | oracle | mysql | 3.23.55 | Yes |
Application | oracle | mysql | 3.23.56 | Yes |
Application | oracle | mysql | 4.0.0 | Yes |
Application | oracle | mysql | 4.0.1 | Yes |
Application | oracle | mysql | 4.0.2 | Yes |
Application | oracle | mysql | 4.0.3 | Yes |
Application | oracle | mysql | 4.0.4 | Yes |
Application | oracle | mysql | 4.0.5 | Yes |
Application | oracle | mysql | 4.0.5a | Yes |
Application | oracle | mysql | 4.0.6 | Yes |
Application | oracle | mysql | 4.0.7 | Yes |
Application | oracle | mysql | 4.0.7 | Yes |
Application | oracle | mysql | 4.0.8 | Yes |
Application | oracle | mysql | 4.0.8 | Yes |
Application | oracle | mysql | 4.0.9 | Yes |
Application | oracle | mysql | 4.0.9 | Yes |
Application | oracle | mysql | 4.0.10 | Yes |
Application | oracle | mysql | 4.0.11 | Yes |
Application | oracle | mysql | 4.0.11 | Yes |
Application | oracle | mysql | 4.0.12 | Yes |
Application | oracle | mysql | 4.0.13 | Yes |
Application | oracle | mysql | 4.0.14 | Yes |
Application | oracle | mysql | 4.1.0 | Yes |
Operating System | conectiva | linux | 7.0 | Yes |
Operating System | conectiva | linux | 8.0 | Yes |
Operating System | conectiva | linux | 9.0 | Yes |