PT-2012-6059 · Mariadb+2 · Mariadb+3

Huzaifa Sidhpurwala

·

Published

2012-12-03

·

Updated

2024-06-15

·

CVE-2012-5612

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Oracle MySQL versions 5.5.19 through 5.5.28 MariaDB versions 5.5.28a and possibly other versions
Description A heap-based buffer overflow issue allows remote authenticated users to cause a denial of service, resulting in memory corruption and crash, and possibly execute arbitrary code. This can be demonstrated using various database commands, including USE, SHOW TABLES, DESCRIBE, SHOW FIELDS FROM, SHOW COLUMNS FROM, SHOW INDEX FROM, CREATE TABLE, DROP TABLE, ALTER TABLE, DELETE FROM, UPDATE, and SET PASSWORD.
Recommendations For Oracle MySQL versions 5.5.19 through 5.5.28, update to a version outside of this range to resolve the issue. For MariaDB versions 5.5.28a and possibly other versions, consider restricting access to the affected database commands as a temporary workaround until a patch is available.

Exploit

Fix

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-5612
OPENSUSE-SU-2024:10153-1
SUSE-RU-2023:3956-1
SUSE-RU-2023:4991-1

Affected Products

Mariadb
Mariadb Server
Mysql Server
Suse