Lucene search

K
ubuntucveUbuntu.comUB:CVE-2013-1492
HistoryMar 28, 2013 - 12:00 a.m.

CVE-2013-1492

2013-03-2800:00:00
ubuntu.com
ubuntu.com
21

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.026

Percentile

90.4%

Buffer overflow in yaSSL, as used in MySQL 5.1.x before 5.1.68 and 5.5.x
before 5.5.30, has unspecified impact and attack vectors, a different
vulnerability than CVE-2012-0553.

Notes

Author Note
jdstrand mysql-cluster-7.0 not supported per Ubuntu Server team As of 2012/01/09, Oracle no longer supports MySQL 5.0. Unfortunately, because of upstream update and commit policies it is not possible to backport patches from later releases. Ubuntu is regrettably unable to support MySQL 5.0 and users are encouraged to upgrade to Ubuntu 10.04 LTS or later.
OSVersionArchitecturePackageVersionFilename
ubuntu11.10noarchmysql-5.1< 5.1.69-0ubuntu0.11.10.1UNKNOWN
ubuntu12.04noarchmysql-5.5< 5.5.31-0ubuntu0.12.04.1UNKNOWN
ubuntu12.10noarchmysql-5.5< 5.5.31-0ubuntu0.12.10.1UNKNOWN
ubuntu13.04noarchmysql-5.5< 5.5.31-0ubuntu0.13.04.1UNKNOWN
ubuntu10.04noarchmysql-dfsg-5.1< 5.1.69-0ubuntu0.10.04.1UNKNOWN

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.026

Percentile

90.4%