CVE-2006-7232
Severity CVSS v4.0:
Pending analysis
Type:
CWE-89
SQL Injection
Publication date:
31/12/2006
Last modified:
09/04/2025
Description
sql_select.cc in MySQL 5.0.x before 5.0.32 and 5.1.x before 5.1.14 allows remote authenticated users to cause a denial of service (crash) via an EXPLAIN SELECT FROM on the INFORMATION_SCHEMA table, as originally demonstrated using ORDER BY.
Impact
Base Score 2.0
3.50
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:mysql:mysql:*:*:*:*:*:*:*:* | 5.0 (including) | 5.0.32 (excluding) |
| cpe:2.3:a:mysql:mysql:*:*:*:*:*:*:*:* | 5.1 (including) | 5.1.14 (excluding) |
| cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:lts:*:*:* | ||
| cpe:2.3:o:canonical:ubuntu_linux:6.10:*:*:*:*:*:*:* | ||
| cpe:2.3:o:canonical:ubuntu_linux:7.04:*:*:*:*:*:*:* | ||
| cpe:2.3:o:canonical:ubuntu_linux:7.10:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://bugs.mysql.com/bug.php?id=22413
- http://dev.mysql.com/doc/refman/5.0/en/releasenotes-es-5-0-32.html
- http://dev.mysql.com/doc/refman/5.1/en/news-5-1-14.html
- http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.html
- http://secunia.com/advisories/29443
- http://secunia.com/advisories/30351
- http://secunia.com/advisories/31687
- http://www.redhat.com/support/errata/RHSA-2008-0364.html
- http://www.securityfocus.com/bid/28351
- http://www.ubuntu.com/usn/usn-588-1
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11720
- http://bugs.mysql.com/bug.php?id=22413
- http://dev.mysql.com/doc/refman/5.0/en/releasenotes-es-5-0-32.html
- http://dev.mysql.com/doc/refman/5.1/en/news-5-1-14.html
- http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.html
- http://secunia.com/advisories/29443
- http://secunia.com/advisories/30351
- http://secunia.com/advisories/31687
- http://www.redhat.com/support/errata/RHSA-2008-0364.html
- http://www.securityfocus.com/bid/28351
- http://www.ubuntu.com/usn/usn-588-1
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11720



