<title>MySQL: Two Denial of Service vulnerabilities</title>
Two Denial of Service vulnerabilities have been discovered in MySQL.
<announced>May 08, 2007</announced>
<revised>May 08, 2007: 01</revised>
MySQL is a popular multi-threaded, multi-user SQL server.
mu-b discovered a NULL pointer dereference in when
processing certain types of SQL requests. Sec Consult also discovered
another NULL pointer dereference when sorting certain types of queries
on the database metadata.
In both cases, a remote attacker could send a specially crafted SQL
request to the server, possibly resulting in a server crash. Note that
the attacker needs the ability to execute SELECT queries.
All MySQL users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose &quot;&gt;=dev-db/mysql-5.0.38&quot;</code>
