CVE-2009-2446 describes multiple format string vulnerabilities within the dispatch_command function of MySQL versions 4.0.0 through 5.0.83. An authenticated remote attacker can exploit these flaws by injecting format string specifiers into a database name during COM_CREATE_DB or COM_DROP_DB requests, leading to a denial of service (daemon crash) and potentially other unspecified impacts. The vulnerability has a high CVSS score of 8.5, indicating a severe risk due to its network-based attack vector, medium complexity, and complete impact on confidentiality, integrity, and availability. While not listed on CISA's KEV catalog and showing no active exploitation or significant community discussion, an ExploitDB entry exists for MySQL 5.0.75, suggesting public exploit code availability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.1.0CPE matchmatch criteria | cpe:2.3:a:mysql:mysql:4.1.0:*:*:*:*:*:*:* | ||
4.1.2CPE matchmatch criteria | cpe:2.3:a:mysql:mysql:4.1.2:*:*:*:*:*:*:* | ||
4.1.3CPE matchmatch criteria | cpe:2.3:a:mysql:mysql:4.1.3:*:*:*:*:*:*:* | ||
4.1.8CPE matchmatch criteria | cpe:2.3:a:mysql:mysql:4.1.8:*:*:*:*:*:*:* | ||
4.1.10CPE matchmatch criteria | cpe:2.3:a:mysql:mysql:4.1.10:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:S/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.