DescriptionThe in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40, and 5.1 before 5.1.18-beta, allows context-dependent attackers to cause a denial of service (crash) via a crafted IF clause that results in a divide-by-zero error and a NULL pointer dereference.
Overall state of this security issue: Resolved
This issue is currently rated as having important severity.
|National Vulnerability Database|
SUSE Security Advisories:
SUSE Timeline for this CVECVE page created: Fri Jun 28 03:33:31 2013
CVE page last modified: Thu Dec 7 12:25:14 2023