Candidate: CVE-2010-3064 PublicDate: 2010-08-20 20:00:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3064 Description: Stack-based buffer overflow in the php_mysqlnd_auth_write function in the Mysqlnd extension in PHP 5.3 through 5.3.2 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) username or (2) database name argument to the (a) mysql_connect or (b) mysqli_connect function. Ubuntu-Description: Notes: Bugs: Priority: negligible Discovered-by: Assigned-to: CVSS: Patches_php5: upstream_php5: released (5.3.3) dapper_php5: not-affected (code not built) hardy_php5: not-affected (code not built) jaunty_php5: not-affected (code not built) karmic_php5: not-affected (code not built) lucid_php5: not-affected (code not built) devel_php5: not-affected