Affected Versions:
Oracle MySQL 5.1.48-bzrracle MySQL 5.1.47Oracle MySQL 5.1.41
Vulnerability description:
Bugtraq id: 12798mysql is a widely used open-source relational database system with running versions on various platforms. If you use the create temporary table command to CREATE a temporary table and use the innodb engine, the database will crash.
<* Reference
Http://bugs.mysql.com/bug.php? Id = 54044
*>Test method:
The Program (method) provided on this site may be offensive and only used for security research and teaching. You are at your own risk!
Mysql> SET storage_engine = MYISAM; mysql> create temporary table mk_upgrade as select if (null is not null, NULL, NULL); drop table mk_upgrade;
Vendor patch: Oracle ------ the vendor has released a patch to fix this security problem, please go to the vendor's home page download: http://dev.mysql.com/doc/refman/5.1/en/news-5-1-49.html