CVE-2003-0780 describes a critical buffer overflow vulnerability in the get_salt_from_password function of MySQL versions 4.0.14 and earlier, and 3.23.x. This flaw allows authenticated attackers with ALTER TABLE privileges to execute arbitrary code by supplying an excessively long Password field, impacting various Linux distributions and Oracle MySQL products. The vulnerability carries a CVSS score of 9.0, indicating high severity. It is easily exploitable over the network with low attack complexity, and successful exploitation can lead to complete compromise of confidentiality, integrity, and availability. While not listed on the CISA KEV catalog or Hot List, exploit code for this vulnerability is publicly available on ExploitDB. Despite its age and the availability of exploit code, there is no evidence of active exploitation in the wild, nor significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.1.0CPE matchmatch criteria | cpe:2.3:a:mysql:mysql:4.1.0:*:*:*:*:*:*:* | ||
3.23CPE matchmatch criteria | cpe:2.3:a:oracle:mysql:3.23:*:*:*:*:*:*:* | ||
3.23.2CPE matchmatch criteria | cpe:2.3:a:oracle:mysql:3.23.2:*:*:*:*:*:*:* | ||
3.23.3CPE matchmatch criteria | cpe:2.3:a:oracle:mysql:3.23.3:*:*:*:*:*:*:* | ||
3.23.4CPE matchmatch criteria | cpe:2.3:a:oracle:mysql:3.23.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:S/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.