CVE-2009-4019
Last modified
CVE-2009-4019 is a vulnerability of currently unknown severity. mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of certain SELECT statements with subqueries, and does not (2) preserve certain null_value flags during execution of statements that use the GeomFromWKB function, which allows remote authenticated users to cause a denial of service (daemon crash) via a crafted statement.. EPSS estimates a 16.26% chance of exploitation in the next 30 days.
Description
mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of certain SELECT statements with subqueries, and does not (2) preserve certain null_value flags during execution of statements that use the GeomFromWKB function, which allows remote authenticated users to cause a denial of service (daemon crash) via a crafted statement.
Metrics
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Mysql | Mysql | 5.0.0 | — |
| Mysql | Mysql | 5.0.1 | — |
| Mysql | Mysql | 5.0.2 | — |
| Mysql | Mysql | 5.0.3 | — |
| Mysql | Mysql | 5.0.4 | — |
| Mysql | Mysql | 5.0.5 | — |
| Mysql | Mysql | 5.0.5.0.21 | — |
| Mysql | Mysql | 5.0.10 | — |
| Mysql | Mysql | 5.0.15 | — |
| Mysql | Mysql | 5.0.16 | — |
| Mysql | Mysql | 5.0.17 | — |
| Mysql | Mysql | 5.0.20 | — |
| Mysql | Mysql | 5.0.22.1.0.1 | — |
| Mysql | Mysql | 5.0.24 | — |
| Mysql | Mysql | 5.0.30 | — |
| Mysql | Mysql | 5.0.36 | — |
| Mysql | Mysql | 5.0.44 | — |
| Mysql | Mysql | 5.0.54 | — |
| Mysql | Mysql | 5.0.56 | — |
| Mysql | Mysql | 5.0.60 | — |
| Mysql | Mysql | 5.0.66 | — |
| Mysql | Mysql | 5.0.82 | — |
| Mysql | Mysql | 5.1.5 | — |
| Mysql | Mysql | 5.1.23 | — |
| Mysql | Mysql | 5.1.32 | — |
| Oracle | Mysql | 5.0.0 | Alpha |
| Oracle | Mysql | 5.0.3 | Beta |
| Oracle | Mysql | 5.0.6 | — |
| Oracle | Mysql | 5.0.7 | — |
| Oracle | Mysql | 5.0.8 | — |
| Oracle | Mysql | 5.0.11 | — |
| Oracle | Mysql | 5.0.12 | — |
| Oracle | Mysql | 5.0.13 | — |
| Oracle | Mysql | 5.0.14 | — |
| Oracle | Mysql | 5.0.18 | — |
| Oracle | Mysql | 5.0.19 | — |
| Oracle | Mysql | 5.0.21 | — |
| Oracle | Mysql | 5.0.22 | — |
| Oracle | Mysql | 5.0.23 | — |
| Oracle | Mysql | 5.0.25 | — |
| Oracle | Mysql | 5.0.26 | — |
| Oracle | Mysql | 5.0.27 | — |
| Oracle | Mysql | 5.0.30 | Sp1 |
| Oracle | Mysql | 5.0.32 | — |
| Oracle | Mysql | 5.0.33 | — |
| Oracle | Mysql | 5.0.37 | — |
| Oracle | Mysql | 5.0.38 | — |
| Oracle | Mysql | 5.0.41 | — |
| Oracle | Mysql | 5.0.42 | — |
| Oracle | Mysql | 5.0.45 | — |
Showing 50 of 81 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-4019?
How severe is CVE-2009-4019?
How do I fix CVE-2009-4019?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-4013Multiple directory traversal vulnerabilities in Lintian 1.23…9.8
- CVE-2009-4014Multiple format string vulnerabilities in Lintian 1.23.x thr…
- CVE-2009-4015Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and…
- CVE-2009-4016Integer underflow in the clean_string function in irc_string…
- CVE-2009-4017PHP before 5.2.12 and 5.3.x before 5.3.1 does not restrict t…
- CVE-2009-4018The proc_open function in ext/standard/proc_open.c in PHP be…
- CVE-2009-4020Stack-based buffer overflow in the hfs subsystem in the Linu…
- CVE-2009-4021The fuse_direct_io function in fs/fuse/file.c in the fuse su…
- CVE-2009-4022Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9…
- CVE-2009-4023Argument injection vulnerability in the sendmail implementat…
- CVE-2009-4024Argument injection vulnerability in the ping function in Pin…
- CVE-2009-4025Argument injection vulnerability in the traceroute function …
Are you affected by CVE-2009-4019?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
