Vulnerability Name:

CVE-2004-0837 (CCN-17667)

Assigned:2004-10-11
Published:2004-10-11
Updated:2019-12-17
Summary:MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows attackers to cause a denial of service (crash or hang) via multiple threads that simultaneously alter MERGE table UNIONs.
CVSS v3 Severity:3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:2.6 Low (CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
2.6 Low (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Denial of Service
References:Source: MISC
Type: Exploit, Vendor Advisory
http://bugs.mysql.com/2408

Source: CCN
Type: MySQL Bugs: #2408
Multiple threads altering MERGE table UNIONs hang/crash

Source: MITRE
Type: CNA
CVE-2004-0837

Source: CCN
Type: MySQL Download Web page
MySQL 4.0 Downloads

Source: CONECTIVA
Type: Broken Link
CLA-2004:892

Source: CCN
Type: Conectiva Linux Security Announcement CLSA-2004:892
Fixes for several mysql vulnerabilities

Source: MISC
Type: Vendor Advisory
http://lists.mysql.com/internals/16168

Source: MISC
Type: Vendor Advisory
http://lists.mysql.com/internals/16173

Source: MISC
Type: Vendor Advisory
http://lists.mysql.com/internals/16174

Source: BUGTRAQ
Type: Mailing List, Third Party Advisory
20041125 [USN-32-1] mysql vulnerabilities

Source: MISC
Type: Vendor Advisory
http://mysql.bkbits.net:8080/mysql-3.23/diffs/myisammrg/myrg_open.c@1.15

Source: CCN
Type: RHSA-2004-597
mysql security update

Source: CCN
Type: RHSA-2004-611
mysql-server security update

Source: CCN
Type: SA12783
MySQL Multiple Vulnerabilities

Source: SECUNIA
Type: Third Party Advisory
12783

Source: CCN
Type: SECTRACK ID: 1011606
MySQL May Let Remote Authenticated Users Access Restricted Tables or Crash the System

Source: SECTRACK
Type: Third Party Advisory, VDB Entry
1011606

Source: SUNALERT
Type: Broken Link
101864

Source: CCN
Type: Sun Alert ID: 201658
Multiple Security Vulnerabilities in The "MySQL" Package

Source: CCN
Type: CIAC Information Bulletin P-018
Red Hat Update MySQL Packages Fix Security Issues and Bugs

Source: CIAC
Type: Broken Link
P-018

Source: DEBIAN
Type: Third Party Advisory
DSA-562

Source: DEBIAN
Type: DSA-562
mysql -- several vulnerabilities

Source: CCN
Type: GLSA-200410-22
MySQL: Multiple vulnerabilities

Source: GENTOO
Type: Third Party Advisory
GLSA-200410-22

Source: CCN
Type: MySQL Web site
MySQL:The World's Most Popular Open Source Database

Source: CCN
Type: OpenPKG-SA-2004.045
MySQL

Source: REDHAT
Type: Patch, Vendor Advisory
RHSA-2004:597

Source: REDHAT
Type: Third Party Advisory
RHSA-2004:611

Source: BID
Type: Third Party Advisory, VDB Entry
11357

Source: CCN
Type: BID-11357
MySQL Multiple Local Vulnerabilities

Source: CCN
Type: Trustix Secure Linux Security Advisory #2004-0054
Multiple security vulnerabilities

Source: TRUSTIX
Type: Broken Link
2004-0054

Source: CCN
Type: TLSA-2005-23
Multiple vulnerabilities have been discovered in MySQL

Source: CCN
Type: USN-32-1
mysql vulnerabilities

Source: XF
Type: Third Party Advisory, VDB Entry
mysql-union-dos(17667)

Source: XF
Type: UNKNOWN
mysql-union-dos(17667)

Source: SUSE
Type: SUSE-SR:2004:001
SUSE Security Summary Report

Vulnerable Configuration:Configuration 1:
  • cpe:/a:oracle:mysql:4.1.0:-:*:*:*:*:*:*
  • OR cpe:/a:oracle:mysql:*:*:*:*:*:*:*:* (Version >= 3.20 and < 3.23.49)
  • OR cpe:/a:oracle:mysql:*:*:*:*:*:*:*:* (Version >= 4.0.0 and < 4.0.21)

  • Configuration 2:
  • cpe:/o:debian:debian_linux:3.0:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:oracle:mysql:3.23:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:mysql:4.0.18:*:*:*:*:*:*:*
  • AND
  • cpe:/o:trustix:secure_linux:1.5:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:3.0:*:*:*:*:*:*:*
  • OR cpe:/a:openpkg:openpkg:current:*:*:*:*:*:*:*
  • OR cpe:/o:gentoo:linux:*:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:2.1:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:2.1:*:as:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:2.1:*:es:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:2.1:*:ws:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:2.1:*:aw:*:*:*:*:*
  • OR cpe:/o:conectiva:linux:9.0:*:*:*:*:*:*:*
  • OR cpe:/o:trustix:secure_linux:2.0:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:9.2:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:3::ws:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:3::es:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:3::as:*:*:*:*:*
  • OR cpe:/o:trustix:secure_linux:2.1:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:10.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:3::desktop:*:*:*:*:*
  • OR cpe:/o:fedoraproject:fedora_core:2:*:*:*:*:*:*:*
  • OR cpe:/o:conectiva:linux:10:*:*:*:*:*:*:*
  • OR cpe:/a:openpkg:openpkg:2.1:*:*:*:*:*:*:*
  • OR cpe:/a:openpkg:openpkg:2.2:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:10.1:*:*:*:*:*:*:*
  • OR cpe:/o:sun:solaris:10::sparc:*:*:*:*:*
  • OR cpe:/o:sun:solaris:10::x86:*:*:*:*:*
  • OR cpe:/o:redhat:linux_advanced_workstation:2.1::itanium:*:*:*:*:*
  • OR cpe:/a:redhat:rhel_extras:3:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:10.1::x86-64:*:*:*:*:*
  • OR cpe:/o:turbolinux:turbolinux:*:*:home:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:9.2::amd64:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:10.0::amd64:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:2.1::x86_64:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20040837
    V
    CVE-2004-0837
    2015-11-16
    oval:org.debian:def:562
    V
    several vulnerabilities
    2004-10-11
    BACK
    mysql mysql 4.1.0
    oracle mysql *
    oracle mysql *
    debian debian linux 3.0
    mysql mysql 3.23
    mysql mysql 4.0.18
    trustix secure linux 1.5
    debian debian linux 3.0
    openpkg openpkg current
    gentoo linux *
    mandrakesoft mandrake linux corporate server 2.1
    redhat enterprise linux 2.1
    redhat enterprise linux 2.1
    redhat enterprise linux 2.1
    redhat enterprise linux 2.1
    conectiva linux 9.0
    trustix secure linux 2.0
    mandrakesoft mandrake linux 9.2
    redhat enterprise linux 3
    redhat enterprise linux 3
    redhat enterprise linux 3
    trustix secure linux 2.1
    mandrakesoft mandrake linux 10.0
    redhat enterprise linux 3
    fedoraproject fedora core 2
    conectiva linux 10
    openpkg openpkg 2.1
    openpkg openpkg 2.2
    mandrakesoft mandrake linux 10.1
    sun solaris 10
    sun solaris 10
    redhat linux advanced workstation 2.1
    redhat rhel extras 3
    mandrakesoft mandrake linux 10.1
    turbolinux turbolinux home *
    mandrakesoft mandrake linux 9.2
    mandrakesoft mandrake linux 10.0
    mandrakesoft mandrake linux corporate server 2.1