CVE-2010-3682

UnknownEPSS 11.44%

Last modified

CVE-2010-3682 is a vulnerability of currently unknown severity. Oracle MySQL 5.1 before 5.1.49 and 5.0 before 5.0.92 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by using EXPLAIN with crafted "SELECT ... UNION ... EPSS estimates a 11.44% chance of exploitation in the next 30 days.

Description

Oracle MySQL 5.1 before 5.1.49 and 5.0 before 5.0.92 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by using EXPLAIN with crafted "SELECT ... UNION ... ORDER BY (SELECT ... WHERE ...)" statements, which triggers a NULL pointer dereference in the Item_singlerow_subselect::store function.

Metrics

EPSS Probability
11.44%

95.5th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersionsUpdate
MysqlMysql<= 5.1.48—
MysqlMysql5.1.23—
MysqlMysql5.1.31—
MysqlMysql5.1.32—
MysqlMysql5.1.34—
MysqlMysql5.1.37—
OracleMysql5.1.1—
OracleMysql5.1.2—
OracleMysql5.1.3—
OracleMysql5.1.4—
OracleMysql5.1.10—
OracleMysql5.1.11—
OracleMysql5.1.12—
OracleMysql5.1.13—
OracleMysql5.1.14—
OracleMysql5.1.15—
OracleMysql5.1.16—
OracleMysql5.1.17—
OracleMysql5.1.18—
OracleMysql5.1.19—
OracleMysql5.1.20—
OracleMysql5.1.21—
OracleMysql5.1.22—
OracleMysql5.1.23A
OracleMysql5.1.24—
OracleMysql5.1.25—
OracleMysql5.1.26—
OracleMysql5.1.27—
OracleMysql5.1.28—
OracleMysql5.1.29—
OracleMysql5.1.30—
OracleMysql5.1.31Sp1
OracleMysql5.1.33—
OracleMysql5.1.34Sp1
OracleMysql5.1.35—
OracleMysql5.1.36—
OracleMysql5.1.37Sp1
OracleMysql5.1.38—
OracleMysql5.1.39—
OracleMysql5.1.40—
OracleMysql5.1.41—
OracleMysql5.1.42—
OracleMysql5.1.43—
OracleMysql5.1.44—
OracleMysql5.1.45—
OracleMysql5.1.46—
OracleMysql5.1.47—
MysqlMysql<= 5.0.91—
MysqlMysql5.0.0—
MysqlMysql5.0.1—

Showing 50 of 111 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2010-3682?
Oracle MySQL 5.1 before 5.1.49 and 5.0 before 5.0.92 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by using EXPLAIN with crafted "SELECT ... UNION ... ORDER BY (SELECT ... WHERE ...)" statements, which triggers a NULL pointer dereference in the Item_singlerow_subselect::store function.
How severe is CVE-2010-3682?
Severity scoring for CVE-2010-3682 is pending analysis. The EPSS model estimates a 11.44% probability of exploitation in the next 30 days.
How do I fix CVE-2010-3682?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2010

Are you affected by CVE-2010-3682?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST