CVE-2010-3682

UnknownEPSS 11.44%

Last modified

CVE-2010-3682 is a vulnerability of currently unknown severity. Oracle MySQL 5.1 before 5.1.49 and 5.0 before 5.0.92 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by using EXPLAIN with crafted "SELECT ... UNION ... EPSS estimates a 11.44% chance of exploitation in the next 30 days.

Description

Oracle MySQL 5.1 before 5.1.49 and 5.0 before 5.0.92 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by using EXPLAIN with crafted "SELECT ... UNION ... ORDER BY (SELECT ... WHERE ...)" statements, which triggers a NULL pointer dereference in the Item_singlerow_subselect::store function.

Metrics

EPSS Probability
11.44%

95.5th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersionsUpdate
MysqlMysql<= 5.1.48
MysqlMysql5.1.23
MysqlMysql5.1.31
MysqlMysql5.1.32
MysqlMysql5.1.34
MysqlMysql5.1.37
OracleMysql5.1.1
OracleMysql5.1.2
OracleMysql5.1.3
OracleMysql5.1.4
OracleMysql5.1.10
OracleMysql5.1.11
OracleMysql5.1.12
OracleMysql5.1.13
OracleMysql5.1.14
OracleMysql5.1.15
OracleMysql5.1.16
OracleMysql5.1.17
OracleMysql5.1.18
OracleMysql5.1.19
OracleMysql5.1.20
OracleMysql5.1.21
OracleMysql5.1.22
OracleMysql5.1.23A
OracleMysql5.1.24
OracleMysql5.1.25
OracleMysql5.1.26
OracleMysql5.1.27
OracleMysql5.1.28
OracleMysql5.1.29
OracleMysql5.1.30
OracleMysql5.1.31Sp1
OracleMysql5.1.33
OracleMysql5.1.34Sp1
OracleMysql5.1.35
OracleMysql5.1.36
OracleMysql5.1.37Sp1
OracleMysql5.1.38
OracleMysql5.1.39
OracleMysql5.1.40
OracleMysql5.1.41
OracleMysql5.1.42
OracleMysql5.1.43
OracleMysql5.1.44
OracleMysql5.1.45
OracleMysql5.1.46
OracleMysql5.1.47
MysqlMysql<= 5.0.91
MysqlMysql5.0.0
MysqlMysql5.0.1

Showing 50 of 111 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2010-3682?
Oracle MySQL 5.1 before 5.1.49 and 5.0 before 5.0.92 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by using EXPLAIN with crafted "SELECT ... UNION ... ORDER BY (SELECT ... WHERE ...)" statements, which triggers a NULL pointer dereference in the Item_singlerow_subselect::store function.
How severe is CVE-2010-3682?
Severity scoring for CVE-2010-3682 is pending analysis. The EPSS model estimates a 11.44% probability of exploitation in the next 30 days.
How do I fix CVE-2010-3682?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2010-3682?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST