MySQL ha_innodb.cc convert_search_mode_to_innobase() denial of service
| mysql-hainnodb-dos (38284) |
Description:
MySQL is vulnerable to a denial of service, caused by an error in the convert_search_mode_to_innobase() function in ha_innodb.cc. A remote attacker with ALTER privileges could exploit this vulnerability to cause the database server to crash.
Platforms Affected:
- Canonical, Ubuntu 6.06 LTS
- Canonical, Ubuntu 6.10
- Canonical, Ubuntu 7.04
- Canonical, Ubuntu 7.10
- Debian, Debian Linux 3.1
- Debian, Debian Linux 4.0
- Gentoo, Linux
- MandrakeSoft, Mandrake Linux 2007 X86_64
- MandrakeSoft, Mandrake Linux 2007
- MandrakeSoft, Mandrake Linux 2007.1 X86_64
- MandrakeSoft, Mandrake Linux 2007.1
- MandrakeSoft, Mandrake Linux 2008.0
- MandrakeSoft, Mandrake Linux 2008.0 X86_64
- MandrakeSoft, Mandrake Linux Corporate Server 4.0
- MandrakeSoft, Mandrake Linux Corporate Server 4.0 X86_64
- MySQL, MySQL 5.0.44
- MySQL, MySQL 5.1.16.17
- MySQL, MySQL 5.1.23_BK
- RedHat, Application Stack v1 for EL AS 4
- RedHat, Application Stack v1 for EL ES 4
- RedHat, Enterprise Linux 4 ES
- RedHat, Enterprise Linux 4 AS
- RedHat, Enterprise Linux 4 Desktop
- RedHat, Enterprise Linux 4 WS
- RedHat, Enterprise Linux 5 Client Workstation
- RedHat, Enterprise Linux 5
- RedHat, Enterprise Linux 5 Client
- RedHat, RHEL Application Stack 2
Remedy:
For Gentoo Linux (MySQL):
Refer to GLSA 200711-25 for patch, upgrade, or suggested workaround information. See References.
Consequences:
Denial of Service
References:
- Full-Disclosure Mailing List, Tue Nov 06 2007 - 00:38:36 CST, MySQL 5.x DoS (unknown) at http://archives.neohapsis.com/archives/fulldisclosure/2007-11/0158.html.
- MySQL Bug #32125, Database crash due to ha_innodb.cc:3896: ulint convert_search_mode_to_innobase at http://bugs.mysql.com/bug.php?id=32125.
- MySQL Web site, MySQL AB :: The world's most popular open source database at http://www.mysql.com/.
- ASA-2007-535: MySQL security update (RHSA-2007-1155)
- ASA-2008-018: mysql security update (RHSA-2007-1157)
- BID-26353: MySQL Server InnoDB CONVERT_SEARCH_MODE_TO_INNOBASE Function Denial Of Service Vulnerability
- CVE-2007-5925: The convert_search_mode_to_innobase function in ha_innodb.cc in the InnoDB engine in MySQL 5.1.23-BK and earlier allows remote authenticated users to cause a denial of service (database crash) via a certain CONTAINS operation on an indexed column, which triggers an assertion error.
- DSA-1413: mysql -- multiple vulnerabilities
- FrSIRT/ADV-2007-3903: MySQL convert_search_mode_to_innobase() Denial of Service Issue
- GLSA-200711-25: MySQL: Denial of Service
- MDKSA-2007:243: Updated MySQL packages fix multiple vulnerabilities
- RHSA-2007-1155: Important: mysql security update
- RHSA-2007-1157: Important: mysql security update
- SA27568: MySQL InnoDB Denial of Service Vulnerability
- SECTRACK ID: 1018978: MySQL convert_search_mode_to_innobase() Bug Lets Remote Authenticated Users Deny Service
- SUSE-SR:2008:003: SUSE Security Summary Report
- USN-559-1: MySQL vulnerabilities
Reported:
Nov 05, 2007
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
Copyright (c) 1994-2008 Internet Security Systems, Inc. All rights reserved worldwide.
For corrections or additions please email xforce@iss.net
