Summary
The remote host is missing an update to mysql-dfsg-5.0 announced via advisory DSA 1877-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201877-1
Insight
In MySQL 4.0.0 through 5.0.83, multiple format string vulnerabilities in the dispatch_command() function in libmysqld/sql_parse.cc in mysqld allow remote authenticated users to cause a denial of service (daemon crash) and potentially the execution of arbitrary code via format string specifiers in a database name in a COM_CREATE_DB or COM_DROP_DB request.
For the stable distribution (lenny), this problem has been fixed in version 5.0.51a-24+lenny2.
For the old stable distribution (etch), this problem has been fixed in version 5.0.32-7etch11.
We recommend that you upgrade your mysql packages.
Severity
Classification
-
CVE CVE-2009-2446 -
CVSS Base Score: 8.5
AV:N/AC:M/Au:S/C:C/I:C/A:C
Related Vulnerabilities