CVE-2010-3833
Publication date 5 November 2010
Last updated 24 July 2024
Ubuntu priority
MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 does not properly propagate type errors, which allows remote attackers to cause a denial of service (server crash) via crafted arguments to extreme-value functions such as (1) LEAST and (2) GREATEST, related to KILL_BAD_DATA and a “CREATE TABLE ... SELECT.”
Status
Package | Ubuntu Release | Status |
---|---|---|
mysql-5.1 | 11.10 oneiric |
Not affected
|
11.04 natty |
Not affected
|
|
10.10 maverick |
Fixed 5.1.49-1ubuntu8.1
|
|
10.04 LTS lucid | Not in release | |
9.10 karmic | Not in release | |
8.04 LTS hardy | Not in release | |
6.06 LTS dapper | Not in release | |
mysql-cluster-7.0 | 11.10 oneiric | Ignored |
11.04 natty | Ignored | |
10.10 maverick | Ignored | |
10.04 LTS lucid | Ignored | |
9.10 karmic | Not in release | |
8.04 LTS hardy | Not in release | |
6.06 LTS dapper | Not in release | |
mysql-dfsg-5.0 | 11.10 oneiric | Not in release |
11.04 natty | Not in release | |
10.10 maverick | Not in release | |
10.04 LTS lucid | Not in release | |
9.10 karmic | Ignored end of life | |
8.04 LTS hardy |
Fixed 5.0.51a-3ubuntu5.8
|
|
6.06 LTS dapper |
Not affected
|
|
mysql-dfsg-5.1 | 11.10 oneiric | Not in release |
11.04 natty | Not in release | |
10.10 maverick | Not in release | |
10.04 LTS lucid |
Fixed 5.1.41-3ubuntu12.7
|
|
9.10 karmic |
Fixed 5.1.37-1ubuntu5.5
|
|
8.04 LTS hardy | Not in release | |
6.06 LTS dapper | Not in release |
Notes
Patch details
Package | Patch details |
---|---|
mysql-dfsg-5.1 |
References
Related Ubuntu Security Notices (USN)
- USN-1017-1
- MySQL vulnerabilities
- 11 November 2010
- USN-1397-1
- MySQL vulnerabilities
- 12 March 2012