Lucene search

K
cve[email protected]CVE-2013-1861
HistoryMar 28, 2013 - 11:55 p.m.

CVE-2013-1861

2013-03-2823:55:01
CWE-119
web.nvd.nist.gov
144
cve-2013-1861
mariadb
oracle
mysql
denial of service
crash
vulnerability
nvd

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

5.1 Medium

AI Score

Confidence

High

0.901 High

EPSS

Percentile

98.8%

MariaDB 5.5.x before 5.5.30, 5.3.x before 5.3.13, 5.2.x before 5.2.15, and 5.1.x before 5.1.68, and Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote attackers to cause a denial of service (crash) via a crafted geometry feature that specifies a large number of points, which is not properly handled when processing the binary representation of this feature, related to a numeric calculation error.

Affected configurations

NVD
Node
mariadbmariadbRange5.5.0–5.5.32
OR
mariadbmariadbRange10.0.0–10.0.4
Node
oraclemysqlRange5.1.0–5.1.69
OR
oraclemysqlRange5.5.0–5.5.31
OR
oraclemysqlRange5.6.0–5.6.11
Node
redhatenterprise_linuxMatch5
OR
redhatenterprise_linuxMatch6.0
Node
mariadbmariadbRange5.5.0–5.5.32
OR
mariadbmariadbRange10.0.0–10.0.4
Node
debiandebian_linuxMatch7.0
Node
canonicalubuntu_linuxMatch10.04-
OR
canonicalubuntu_linuxMatch12.04-
OR
canonicalubuntu_linuxMatch12.10
OR
canonicalubuntu_linuxMatch13.04
Node
opensuseopensuseMatch11.4
OR
opensuseopensuseMatch12.2
OR
opensuseopensuseMatch12.3
OR
suselinux_enterprise_desktopMatch11sp3
OR
suselinux_enterprise_serverMatch11sp3-
OR
suselinux_enterprise_serverMatch11sp3vmware
OR
suselinux_enterprise_software_development_kitMatch11sp3

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

5.1 Medium

AI Score

Confidence

High

0.901 High

EPSS

Percentile

98.8%