PT-2012-6062 · Mariadb+5 · Mariadb+6

Huzaifa Sidhpurwala

·

Publicado

2012-12-03

·

Atualizado

2024-06-15

·

CVE-2012-5615

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Oracle MySQL versions 5.5.38 and earlier Oracle MySQL versions 5.6.19 and earlier MariaDB versions 5.5.28a and earlier MariaDB version 5.3.11 MariaDB version 5.2.13 MariaDB version 5.1.66
Description The issue allows remote attackers to enumerate valid usernames by generating different error messages with different time delays depending on whether a user name exists.
Recommendations For Oracle MySQL versions 5.5.38 and earlier, update to a version later than 5.5.38 to resolve the issue. For Oracle MySQL versions 5.6.19 and earlier, update to a version later than 5.6.19 to resolve the issue. For MariaDB versions 5.5.28a and earlier, consider updating to a newer version to mitigate the risk. For MariaDB version 5.3.11, consider updating to a newer version to mitigate the risk. For MariaDB version 5.2.13, consider updating to a newer version to mitigate the risk. For MariaDB version 5.1.66, consider updating to a newer version to mitigate the risk. As a temporary workaround, consider restricting access to the user enumeration functionality to minimize the risk of exploitation.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CESA-2014_1861
CVE-2012-5615
DSA-3054-1
OPENSUSE-SU-2024:10153-1
RHSA-2014:1859
RHSA-2014:1860
RHSA-2014:1861
RHSA-2014:1862
RHSA-2014:1937
RHSA-2014:1940
RHSA-2014_1859
RHSA-2014_1861
SUSE-RU-2023:3956-1
SUSE-RU-2023:4991-1
SUSE-SU-2015:0743-1
SUSE-SU-2015_0620-1
USN-2384-1

Produtos afetados

Centos
Mariadb
Mariadb Server
Mysql Server
Red Hat
Suse
Ubuntu