CVE-2002-0969
Last modified
CVE-2002-0969 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Buffer overflow in MySQL daemon (mysqld) before 3.23.50, and 4.0 beta before 4.02, on the Win32 platform, allows local users to execute arbitrary code via a long "datadir" parameter in the my.ini initialization file, whose permissions on Windows allow Full Control to the Everyone group.. EPSS estimates a 1.45% chance of exploitation in the next 30 days.
Description
Buffer overflow in MySQL daemon (mysqld) before 3.23.50, and 4.0 beta before 4.02, on the Win32 platform, allows local users to execute arbitrary code via a long "datadir" parameter in the my.ini initialization file, whose permissions on Windows allow Full Control to the Everyone group.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Mysql | < 3.23.50 |
| Oracle | Mysql | >= 4.0.0, <= 4.0.2 |
References
- http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0004.htmlBroken Link, Exploit, Patch, Vendor Advisory
- http://www.iss.net/security_center/static/10243.phpBroken Link, Vendor Advisory
- http://www.securityfocus.com/bid/5853Broken Link, Third Party Advisory, VDB Entry
- http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0004.htmlBroken Link, Exploit, Patch, Vendor Advisory
- http://www.iss.net/security_center/static/10243.phpBroken Link, Vendor Advisory
- http://www.securityfocus.com/bid/5853Broken Link, Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2002-0969?
How severe is CVE-2002-0969?
How do I fix CVE-2002-0969?
Are you affected by CVE-2002-0969?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
