MySQL Community Server 5.1 < 5.1.32 XPath Expression DoS
medium Log Correlation Engine Plugin ID 801118
Synopsis
The remote host is vulnerable to a Denial of Service (DoS) attack.
Description
The version of MySQL 5.1 installed on the remote host is earlier than 5.1.32 and is affected by a denial of service vulnerability. Specifically, a user can cause an assertion failure leading to a server crash by calling 'ExtractValue()' or 'UpdateXML()' using an XPath expression employing a scalar expression as a 'FilterExpr'.