This application requires Javascript for optimal performance.

Sun.MySQL.Dispatch.Command.Format.String

Release Date

Aug 18, 2009

Severity

high

Impact

Denial of Service: Remote attackers can crash vulnerable systems.

Description

This indicates an attack attempt against a format string vulnerability in Sun Microsystems MySQL database server.

The vulnerability is caused by an error when the vulnerable software handles a specially crafted create or drop database command. It allows a remote attacker to cause a denial of service (daemon crash).

Affected Products

MySQL 5.x
MySQL 4.x

Recommended Actions

Upgrade to the latest version:
http://dev.mysql.com/downloads/

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2009-2446

Reference/s

http://www.securityfocus.com/bid/35609 (BugTraq)
http://www.frsirt.com/english/advisories/2009/1857 (FrSIRT)

Reference: VID-17621