CVE-2004-0836

Publication date 3 November 2004

Last updated 24 July 2024


Ubuntu priority

Buffer overflow in the mysql_real_connect function in MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows remote DNS servers to cause a denial of service and possibly execute arbitrary code via a DNS response with a large address length (h_length).

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
mysql-dfsg 7.04 feisty Not in release
6.10 edgy
Fixed 4.0.24-10ubuntu2
6.06 LTS dapper
Fixed 4.0.24-10ubuntu2

References

Related Ubuntu Security Notices (USN)

    • USN-32-1
    • mysql vulnerabilities
    • 25 November 2004

Other references