PT-2012-6062 · Mariadb+5 · Mariadb+6

Huzaifa Sidhpurwala

·

Published

2012-12-03

·

Updated

2024-06-15

·

CVE-2012-5615

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Oracle MySQL versions 5.5.38 and earlier Oracle MySQL versions 5.6.19 and earlier MariaDB versions 5.5.28a and earlier MariaDB version 5.3.11 MariaDB version 5.2.13 MariaDB version 5.1.66
Description The issue allows remote attackers to enumerate valid usernames by generating different error messages with different time delays depending on whether a user name exists.
Recommendations For Oracle MySQL versions 5.5.38 and earlier, update to a version later than 5.5.38 to resolve the issue. For Oracle MySQL versions 5.6.19 and earlier, update to a version later than 5.6.19 to resolve the issue. For MariaDB versions 5.5.28a and earlier, consider updating to a newer version to mitigate the risk. For MariaDB version 5.3.11, consider updating to a newer version to mitigate the risk. For MariaDB version 5.2.13, consider updating to a newer version to mitigate the risk. For MariaDB version 5.1.66, consider updating to a newer version to mitigate the risk. As a temporary workaround, consider restricting access to the user enumeration functionality to minimize the risk of exploitation.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CESA-2014_1861
CVE-2012-5615
DSA-3054-1
OPENSUSE-SU-2024:10153-1
RHSA-2014:1859
RHSA-2014:1860
RHSA-2014:1861
RHSA-2014:1862
RHSA-2014:1937
RHSA-2014:1940
RHSA-2014_1859
RHSA-2014_1861
SUSE-RU-2023:3956-1
SUSE-RU-2023:4991-1
SUSE-SU-2015:0743-1
SUSE-SU-2015_0620-1
USN-2384-1

Affected Products

Centos
Mariadb
Mariadb Server
Mysql Server
Red Hat
Suse
Ubuntu