Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

MySQL Password Handler Buffer Overflow Vulnerability

MySQL server has been reported prone to a buffer overflow vulnerability when handling user passwords of excessive size.

The issue presents itself, due to a lack of sufficient bounds checking performed when processing MySQL user passwords. A password greater that 16 characters may overrun the bounds of a reserved buffer in memory and corrupt adjacent memory. An attacker with global administrative privileges on an affected MySQL server may potentially exploit this condition to have arbitrary supplied instructions executed in the context of the MySQL server.







 

Privacy Statement
Copyright 2008, SecurityFocus