CVE-2004-0627

NameCVE-2004-0627
DescriptionThe check_scramble_323 function in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to bypass authentication via a zero-length scrambled string.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs330164, 380507

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
mysqlsource(unstable)(not affected)
mysql-dfsgsource(unstable)(not affected)
mysql-dfsg-4.1source(unstable)4.1.11a-1medium330164, 380507
mysql-dfsg-5.0source(unstable)(not affected)

Notes

- mysql <not-affected> (Apparently 3.2 not exploitable, see #330164)
- mysql-dfsg <not-affected> (Apparently 4.0 not exploitable, see #330164)
- mysql-dfsg-5.0 <not-affected> (Was fixed before MySQL 5.0 was uploaded into the archive)

Search for package or bug name: Reporting problems