Lucene search

K
cve[email protected]CVE-2012-5612
HistoryDec 03, 2012 - 12:49 p.m.

CVE-2012-5612

2012-12-0312:49:43
CWE-787
web.nvd.nist.gov
146
2
oracle mysql
buffer overflow
denial of service
cve-2012-5612
nvd
security vulnerability

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

5.7 Medium

AI Score

Confidence

High

0.961 High

EPSS

Percentile

99.5%

Heap-based buffer overflow in Oracle MySQL 5.5.19 and other versions through 5.5.28, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code, as demonstrated using certain variations of the (1) USE, (2) SHOW TABLES, (3) DESCRIBE, (4) SHOW FIELDS FROM, (5) SHOW COLUMNS FROM, (6) SHOW INDEX FROM, (7) CREATE TABLE, (8) DROP TABLE, (9) ALTER TABLE, (10) DELETE FROM, (11) UPDATE, and (12) SET PASSWORD commands.

Affected configurations

NVD
Node
mariadbmariadbRange5.1.05.1.67
OR
mariadbmariadbRange5.2.05.2.14
OR
mariadbmariadbRange5.3.05.3.12
OR
mariadbmariadbRange5.5.05.5.29
OR
mariadbmariadbMatch10.0.0
Node
oraclemysqlRange5.5.05.5.28
Node
suselinux_enterprise_desktopMatch11sp2
OR
suselinux_enterprise_serverMatch11sp2-
OR
suselinux_enterprise_serverMatch11sp2vmware
OR
suselinux_enterprise_software_development_kitMatch11sp2
Node
canonicalubuntu_linuxMatch10.04-
OR
canonicalubuntu_linuxMatch11.10
OR
canonicalubuntu_linuxMatch12.04-
OR
canonicalubuntu_linuxMatch12.10

Social References

More

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

5.7 Medium

AI Score

Confidence

High

0.961 High

EPSS

Percentile

99.5%