Description
libmysqlclient client library in MySQL 3.x to 3.23.54, and 4.x to 4.0.6, does not properly verify length fields for certain responses in the (1) read_rows or (2) read_one_row routines, which allows remote attackers to cause a denial of service and possibly execute arbitrary code.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2019-2547 Vulnerability (CVE-2019-2547)
WordPress Plugin Custom Post View Generator Cross-Site Scripting (0.4.6)
Jenkins Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2023-27900)
IBM RTC Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-7440)