6.5 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
SINGLE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:S/C:P/I:P/A:P
0.949 High
EPSS
Percentile
99.3%
CentOS Errata and Security Advisory CESA-2012:1551
MySQL is a multi-user, multi-threaded SQL database server. It consists of
the MySQL server daemon (mysqld) and many client programs and libraries.
A stack-based buffer overflow flaw was found in the user permission
checking code in MySQL. An authenticated database user could use this flaw
to crash the mysqld daemon or, potentially, execute arbitrary code with the
privileges of the user running the mysqld daemon. (CVE-2012-5611)
All MySQL users should upgrade to these updated packages, which correct
this issue. After installing this update, the MySQL server daemon (mysqld)
will be restarted automatically.
Merged security bulletin from advisories:
https://lists.centos.org/pipermail/centos-announce/2012-December/081188.html
Affected packages:
mysql
mysql-bench
mysql-devel
mysql-embedded
mysql-embedded-devel
mysql-libs
mysql-server
mysql-test
Upstream details at:
https://access.redhat.com/errata/RHSA-2012:1551
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
CentOS | 6 | i686 | mysql | < 5.1.66-2.el6_3 | mysql-5.1.66-2.el6_3.i686.rpm |
CentOS | 6 | i686 | mysql-bench | < 5.1.66-2.el6_3 | mysql-bench-5.1.66-2.el6_3.i686.rpm |
CentOS | 6 | i686 | mysql-devel | < 5.1.66-2.el6_3 | mysql-devel-5.1.66-2.el6_3.i686.rpm |
CentOS | 6 | i686 | mysql-embedded | < 5.1.66-2.el6_3 | mysql-embedded-5.1.66-2.el6_3.i686.rpm |
CentOS | 6 | i686 | mysql-embedded-devel | < 5.1.66-2.el6_3 | mysql-embedded-devel-5.1.66-2.el6_3.i686.rpm |
CentOS | 6 | i686 | mysql-libs | < 5.1.66-2.el6_3 | mysql-libs-5.1.66-2.el6_3.i686.rpm |
CentOS | 6 | i686 | mysql-server | < 5.1.66-2.el6_3 | mysql-server-5.1.66-2.el6_3.i686.rpm |
CentOS | 6 | i686 | mysql-test | < 5.1.66-2.el6_3 | mysql-test-5.1.66-2.el6_3.i686.rpm |
CentOS | 6 | x86_64 | mysql | < 5.1.66-2.el6_3 | mysql-5.1.66-2.el6_3.x86_64.rpm |
CentOS | 6 | x86_64 | mysql-bench | < 5.1.66-2.el6_3 | mysql-bench-5.1.66-2.el6_3.x86_64.rpm |