← Vulnerability feed

Vulnerability record · CVE-2007-5925 · published 10 November 2007

CVE-2007-5925: Mysql improper input validation vulnerability

Mysql · Mysql

The convert_search_mode_to_innobase function in ha_innodb.cc in the InnoDB engine in MySQL 5.1.23-BK and earlier allows remote authenticated users to cause a denial of service (database crash) via a certain CONTAINS operation on an indexed column, which triggers an assertion error.

4.0 CVSS 2.0 Medium EPSS 11% · top 4.2% CWE-20 · Improper input validation
4.0CVSS 2.0 base score
11%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
56References
16 Jun 2026Last modified by NVD

Description

The convert_search_mode_to_innobase function in ha_innodb.cc in the InnoDB engine in MySQL 5.1.23-BK and earlier allows remote authenticated users to cause a denial of service (database crash) via a certain CONTAINS operation on an indexed column, which triggers an assertion error.

AV:N/AC:L/Au:S/C:N/I:N/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://bugs.gentoo.org/show_bug.cgi?id=198988
http://bugs.mysql.com/bug.php?id=32125
http://lists.grok.org.uk/pipermail/full-disclosure/2007-November/067350.html
http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.html
http://secunia.com/advisories/27568
http://secunia.com/advisories/27649
http://secunia.com/advisories/27823
http://secunia.com/advisories/28025
http://secunia.com/advisories/28040
http://secunia.com/advisories/28099
http://secunia.com/advisories/28108
http://secunia.com/advisories/28128
http://secunia.com/advisories/28838
http://security.gentoo.org/glsa/glsa-200711-25.xml
http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.428959
http://www.debian.org/security/2007/dsa-1413
http://www.mandriva.com/security/advisories?name=MDKSA-2007:243
http://www.redhat.com/support/errata/RHSA-2007-1155.html
http://www.redhat.com/support/errata/RHSA-2007-1157.html
http://www.securityfocus.com/bid/26353
http://www.securitytracker.com/id?1018978
http://www.ubuntu.com/usn/USN-1397-1
http://www.vupen.com/english/advisories/2007/3903
https://exchange.xforce.ibmcloud.com/vulnerabilities/38284
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11390
https://usn.ubuntu.com/559-1/
https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00467.html
https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00475.html
http://bugs.gentoo.org/show_bug.cgi?id=198988
http://bugs.mysql.com/bug.php?id=32125
http://lists.grok.org.uk/pipermail/full-disclosure/2007-November/067350.html
http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.html
http://secunia.com/advisories/27568
http://secunia.com/advisories/27649
http://secunia.com/advisories/27823
http://secunia.com/advisories/28025
http://secunia.com/advisories/28040
http://secunia.com/advisories/28099
http://secunia.com/advisories/28108
http://secunia.com/advisories/28128

Track CVE-2007-5925 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2004-0627MySQL authentication bypass via zero-length scrambled stringThe check_scramble_323 function in MySQL 4.1.x before 4.1.3 and 5.0 fails to properly validate a zero-length scrambled authentication string, allowin…EPSS 70%analysed10.0CVE-2004-0628Mysql vulnerabilityStack-based buffer overflow in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to cause a denial of service (crash) and possibly execute a…EPSS 7.8%9.0CVE-2003-0780MySQL get_salt_from_password buffer overflow allows code executionMySQL 4.0.14 and earlier, plus 3.23.x, contain a buffer overflow in get_salt_from_password in sql_acl.cc. An attacker with ALTER TABLE privileges can…EPSS 78%analysed8.5CVE-2009-2446Mysql vulnerabilityMultiple format string vulnerabilities in the dispatch_command function in libmysqld/sql_parse.cc in mysqld in MySQL 4.0.0 through 5.0.83 allow remot…EPSS 11%7.8CVE-2017-15945Mariadb incorrect permission assignment vulnerabilityThe installation scripts in the Gentoo dev-db/mysql, dev-db/mariadb, dev-db/percona-server, dev-db/mysql-cluster, and dev-db/mariadb-galera packages …EPSS 0.37%7.5CVE-2012-0553Mysql memory buffer overflow vulnerabilityBuffer overflow in yaSSL, as used in MySQL 5.1.x before 5.1.68 and 5.5.x before 5.5.28, has unspecified impact and attack vectors, a different vulner…EPSS 2.6%7.5CVE-2013-1492Mysql memory buffer overflow vulnerabilityBuffer overflow in yaSSL, as used in MySQL 5.1.x before 5.1.68 and 5.5.x before 5.5.30, has unspecified impact and attack vectors, a different vulner…EPSS 2.8%7.5CVE-2012-0882Oracle mysql memory buffer overflow vulnerabilityBuffer overflow in yaSSL, as used in MySQL 5.5.20 and possibly other versions including 5.5.x before 5.5.22 and 5.1.x before 5.1.62, allows remote at…EPSS 5.3%

Source: NIST National Vulnerability Database (record CVE-2007-5925), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.