CVE-2002-0969

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
11/10/2002
Last modified:
03/04/2025

Description

Buffer overflow in MySQL daemon (mysqld) before 3.23.50, and 4.0 beta before 4.02, on the Win32 platform, allows local users to execute arbitrary code via a long "datadir" parameter in the my.ini initialization file, whose permissions on Windows allow Full Control to the Everyone group.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:* 3.23.50 (excluding)
cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:* 4.0.0 (including) 4.0.2 (including)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:x86:*