Skip to main content

CVE-2010-3838

Severity Medium
Score 4/10

Summary

MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 allows remote authenticated users to cause a denial of service (server crash) via a query that uses the (1) GREATEST or (2) LEAST function with a mixed list of numeric and LONGBLOB arguments, which is not properly handled when the function's result is "processed using an intermediate temporary table."

  • LOW
  • NETWORK
  • SINGLE
  • NONE
  • NONE
  • PARTIAL

References

Advisory Timeline

  • Published