{ "schema_version": "1.4.0", "id": "GHSA-654g-56x3-m3r6", "modified": "2022-05-01T02:09:36Z", "published": "2022-05-01T02:09:36Z", "aliases": [ "CVE-2005-2572" ], "details": "MySQL, when running on Windows, allows remote authenticated users with insert privileges on the mysql.func table to cause a denial of service (server hang) and possibly execute arbitrary code via (1) a request for a non-library file, which causes the Windows LoadLibraryEx function to block, or (2) a request for a function in a library that has the XXX_deinit or XXX_init functions defined but is not tailored for mySQL, such as jpeg1x32.dll and jpeg2x32.dll.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2005-2572" }, { "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/21756" }, { "type": "WEB", "url": "http://h20565.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?docId=emr_na-c03897409" }, { "type": "WEB", "url": "http://marc.info/?l=bugtraq&m=112360818900941&w=2" }, { "type": "WEB", "url": "http://secunia.com/advisories/54788" }, { "type": "WEB", "url": "http://www.appsecinc.com/resources/alerts/mysql/2005-003.html" }, { "type": "WEB", "url": "http://www.securityfocus.com/bid/62358" }, { "type": "WEB", "url": "http://www.securitytracker.com/id/1029010" } ], "database_specific": { "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2005-08-16T04:00:00Z" } }