CVE-2002-1375 describes a critical vulnerability in MySQL versions 3.x before 3.23.54 and 4.x up to 4.0.6, where a long response to the COM_CHANGE_USER command can lead to remote arbitrary code execution. This flaw affects various Oracle and Symantec Veritas products utilizing these vulnerable MySQL versions. With a CVSS score of 7.5, it represents a high-severity issue, allowing unauthenticated remote attackers to achieve partial confidentiality, integrity, and availability impacts with low attack complexity. While there is no evidence of active exploitation in the wild or Metasploit/Nuclei modules, an exploit demonstrating password memory corruption is available on ExploitDB, though community discussion and media coverage remain minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.22.26CPE matchmatch criteria | cpe:2.3:a:oracle:mysql:3.22.26:*:*:*:*:*:*:* | ||
3.22.27CPE matchmatch criteria | cpe:2.3:a:oracle:mysql:3.22.27:*:*:*:*:*:*:* | ||
3.22.28CPE matchmatch criteria | cpe:2.3:a:oracle:mysql:3.22.28:*:*:*:*:*:*:* | ||
3.22.29CPE matchmatch criteria | cpe:2.3:a:oracle:mysql:3.22.29:*:*:*:*:*:*:* | ||
3.22.30CPE matchmatch criteria | cpe:2.3:a:oracle:mysql:3.22.30:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.