oss-sec mailing list archives
Re: CVE request: MySQL empty bit-string literal server crash
From: "Steven M. Christey" <coley () linus mitre org>
Date: Tue, 9 Sep 2008 10:31:18 -0400 (EDT)
On Tue, 9 Sep 2008, Robert Buchholz wrote:
An empty bit-string literal (b'') caused a server crash. Now the value is parsed as an empty bit value (which is treated as an empty string in string context or 0 in numeric context). (Bug#35658)
Use CVE-2008-3963. - Steve
Current thread:
- CVE request: MySQL empty bit-string literal server crash Robert Buchholz (Sep 09)
- Re: CVE request: MySQL empty bit-string literal server crash Steven M. Christey (Sep 09)
- Re: CVE request: MySQL incomplete fix for CVE-2008-2079 Tomas Hoger (Sep 09)
- Re: CVE request: MySQL incomplete fix for CVE-2008-2079 Steven M. Christey (Sep 15)