Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Full Disclosure: Re: [AppSecInc Advisory MYSQL05-V0002] Buffer Overflow in MySQL User Defined Functions

Re: [AppSecInc Advisory MYSQL05-V0002] Buffer Overflow in MySQL User Defined Functions

From: David Litchfield <davidl_at_ngssoftware.com>
Date: Tue, 9 Aug 2005 01:38:45 +0100

> Buffer Overflow in MySQL User Defined Functions
> Risk level: LOW
> Credits: This vulnerability was discovered and researched by Reid
> Borsuk of Application Security Inc.

How can this even be marked as low risk? If you're loading a library into
mysql's address space then you're already executing "arbitrary code". It's
important that we, as security researchers, don't desensitize the readership
with pointless "vulnerability" posts otherwise people begin to turn off.
Sure - you've found some sloppy code in mysql - get it looked at by all
means but please don't try to create a risk, whether low or not, where there
really is none.

Cheers,
David "got out of the wrong side of bed this morning" Litchfield

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Received on Aug 08 2005

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]