CVE-2009-0819

UnknownEPSS 10.18%

Last modified

CVE-2009-0819 is a vulnerability of currently unknown severity. sql/item_xmlfunc.cc in MySQL 5.1 before 5.1.32 and 6.0 before 6.0.10 allows remote authenticated users to cause a denial of service (crash) via "an XPath expression employing a scalar expression as a FilterExpr with ExtractValue() or UpdateXML()," which triggers an assertion failure.. EPSS estimates a 10.18% chance of exploitation in the next 30 days.

Description

sql/item_xmlfunc.cc in MySQL 5.1 before 5.1.32 and 6.0 before 6.0.10 allows remote authenticated users to cause a denial of service (crash) via "an XPath expression employing a scalar expression as a FilterExpr with ExtractValue() or UpdateXML()," which triggers an assertion failure.

Metrics

EPSS Probability
10.18%

95.1th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersionsUpdate
MysqlMysql<= 5.1.32-bzr—
MysqlMysql5.1.23—
MysqlMysql5.1.31—
MysqlMysql6.0.9—
MysqlMysql6.0.10-bzr—
OracleMysql5.1—
OracleMysql5.1.1—
OracleMysql5.1.2—
OracleMysql5.1.3—
OracleMysql5.1.10—
OracleMysql5.1.11—
OracleMysql5.1.12—
OracleMysql5.1.13—
OracleMysql5.1.14—
OracleMysql5.1.15—
OracleMysql5.1.16—
OracleMysql5.1.17—
OracleMysql5.1.18—
OracleMysql5.1.19—
OracleMysql5.1.20—
OracleMysql5.1.21—
OracleMysql5.1.22—
OracleMysql5.1.23A
OracleMysql5.1.24—
OracleMysql5.1.25—
OracleMysql5.1.26—
OracleMysql5.1.27—
OracleMysql5.1.28—
OracleMysql5.1.29—
OracleMysql5.1.30—
OracleMysql5.1.31Sp1
OracleMysql6.0.0—
OracleMysql6.0.1—
OracleMysql6.0.2—
OracleMysql6.0.3—
OracleMysql6.0.4—

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2009-0819?
sql/item_xmlfunc.cc in MySQL 5.1 before 5.1.32 and 6.0 before 6.0.10 allows remote authenticated users to cause a denial of service (crash) via "an XPath expression employing a scalar expression as a FilterExpr with ExtractValue() or UpdateXML()," which triggers an assertion failure.
How severe is CVE-2009-0819?
Severity scoring for CVE-2009-0819 is pending analysis. The EPSS model estimates a 10.18% probability of exploitation in the next 30 days.
How do I fix CVE-2009-0819?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2009

Are you affected by CVE-2009-0819?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST