CVE-2004-0836 describes a critical buffer overflow vulnerability in the mysql_real_connect function of MySQL versions 4.x before 4.0.21 and 3.x before 3.23.49, impacting Debian Linux and Oracle MySQL distributions. A remote DNS server can trigger this flaw by sending a DNS response with an excessively large address length (h_length), leading to a denial of service or potentially arbitrary code execution. With a CVSS score of 10.0, this vulnerability is highly severe, allowing unauthenticated remote attackers to compromise affected systems with low attack complexity. Despite its age and high community discussion (10 mentions), there is no known active exploitation, nor are there publicly available Metasploit, Nuclei, or ExploitDB modules.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.20, < 3.23.49CPE matchmatch criteria | cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:* | ||
>= 4.0.0, < 4.0.21CPE matchmatch criteria | cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:3.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.