CVE-2002-1376 describes a denial-of-service and potential arbitrary code execution vulnerability in the libmysqlclient library, affecting MySQL versions 3.x to 3.23.54 and 4.x to 4.0.6, as well as related Oracle and Symantec Veritas products. The flaw stems from improper length field verification in the read_rows or read_one_row routines when processing certain server responses. With a CVSS score of 7.5, this vulnerability is considered highly severe, allowing unauthenticated remote attackers to exploit it with low attack complexity, potentially leading to complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation, no public exploit code (Metasploit, Nuclei, ExploitDB), or KEV listing, the vulnerability has garnered significant community discussion with over 10 mentions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.22.26CPE matchmatch criteria | cpe:2.3:a:oracle:mysql:3.22.26:*:*:*:*:*:*:* | ||
3.22.27CPE matchmatch criteria | cpe:2.3:a:oracle:mysql:3.22.27:*:*:*:*:*:*:* | ||
3.22.28CPE matchmatch criteria | cpe:2.3:a:oracle:mysql:3.22.28:*:*:*:*:*:*:* | ||
3.22.29CPE matchmatch criteria | cpe:2.3:a:oracle:mysql:3.22.29:*:*:*:*:*:*:* | ||
3.22.30CPE matchmatch criteria | cpe:2.3:a:oracle:mysql:3.22.30:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.