Back to Database
Status published
High
CVE-2002-1375
The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x...
Vulnerability Description
The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x to 4.0.6, allows remote attackers to execute arbitrary code via a long response.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2002-1375
Credits & Attribution
No credits recorded in the NVD database.
References
- http://marc.info/?l=bugtraq&m=103971644013961&w=2
- http://marc.info/?l=bugtraq&m=104005886114500&w=2
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000555
- http://www.linuxsecurity.com/advisories/engarde_advisory-2660.html
- http://security.e-matters.de/advisories/042002.html
- http://www.debian.org/security/2002/dsa-212
- http://www.redhat.com/support/errata/RHSA-2002-288.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10848
- http://www.mandrakesoft.com/security/advisories?name=MDKSA-2002:087
- http://www.redhat.com/support/errata/RHSA-2003-166.html
- http://marc.info/?l=bugtraq&m=104004857201968&w=2
- http://www.novell.com/linux/security/advisories/2003_003_mysql.html
- http://www.securityfocus.com/bid/6375
- http://www.redhat.com/support/errata/RHSA-2002-289.html
- http://www.trustix.net/errata/misc/2002/TSL-2002-0086-mysql.asc.txt
- http://www.securityfocus.com/advisories/5269
More from oracle
View All →CVE-2021-3314
Oracle GlassFish Server 3.1.2.18 and below allows /common/logViewer/logViewer.jsf XSS. A...
Medium
6.1
CVE-2020-9315
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web...
High
7.5
CVE-2020-9314
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web...
Medium
4.8
CVE-2019-2413
Vulnerability in the Oracle Reports Developer component of Oracle Fusion...
Medium
6.1
CVE-2018-3209
Vulnerability in the Java SE component of Oracle Java SE...
High
8.3
Affected Vendor
oracle
View all reports →Affected Software
mysql, netbackup advanced reporter, netbackup global data manager
Vulnerable Versions:
3.22.26, 3.22.27, 3.22.28, 3.22.29, 3.22.30, 3.22.32, 3.23.2, 3.23.3, 3.23.4, 3.23.5, 3.23.8, 3.23.9, 3.23.10, 3.23.23, 3.23.24, 3.23.25, 3.23.26, 3.23.27, 3.23.28, 3.23.29, 3.23.30, 3.23.31, 3.23.34, 3.23.36, 3.23.37, 3.23.38, 3.23.39, 3.23.40, 3.23.41, 3.23.42, 3.23.43, 3.23.44, 3.23.45, 3.23.46, 3.23.47, 3.23.48, 3.23.49, 3.23.50, 3.23.51, 3.23.52, 3.23.53, 3.23.53a, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.5a, 3.4, 4.5, 4.5_fp1, 4.5_fp2, 4.5_fp3, 4.5_mp1, 4.5_mp2, 4.5_mp3
Timeline
Official Publish:
September 1st, 2004
Last Modified:
August 8th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.