CVE-2010-3840 PUBLISHED CVSS 4 MEDIUM

The Gis_line_string::init_from_wkb function in sql/spatial.cc in MySQL 5.1 before 5.1.51 allows remote authenticated users to cause a denial of service (server crash) by calling the PolyFromWKB function with Well-Known Binary (WKB) data containing a crafted number of (1) line strings or (2) line points.

EPSS 0.72% · 72.3th percentile

Risk Scores

CVSS v2.0
4
EPSS Score
0.72%
72.3th percentile

Affected Products

VendorProductVersions
oraclemysql5.1.50, 5.1.45, 5.1.46
n/an/an/a
mysqlmysql5.1.23, 5.1.31, 5.1.5

Timeline

References

…and 1 more

Open in Interactive Console →