Security Advisory

CVE-2010-3064

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2010-08-20 19:00:00
Last updated 2024-08-07 02:55:46
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Stack-based buffer overflow in the php_mysqlnd_auth_write function in the Mysqlnd extension in PHP 5.3 through 5.3.2 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) username or (2) database name argument to the (a) mysql_connect or (b) mysqli_connect function.