CVE-2012-5614
MySQL - Denial of Service (PoC)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Oracle MySQL 5.1.67 and earlier and 5.5.29 and earlier, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a denial of service (mysqld crash) via a SELECT command with an UpdateXML command containing XML with a large number of unique, nested elements.
MySQL v5.5.19 y posiblemente otras versiones, y MariaDB v5.5.28a y posiblemente otras versiones, permiten a usuarios remotos autenticados provocar una denegación de servicio (caída de mysqld) a través de un comando SELECT con un comando updateXML que contiene XML con un gran número de elementos anidados "unique".
Multiple vulnerabilities have been found in MySQL, allowing attackers to execute arbitrary code or cause Denial of Service. Versions less than 5.1.70 are affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-10-24 CVE Reserved
- 2012-12-02 First Exploit
- 2012-12-03 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (13)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/53372 | Not Applicable | |
http://www.openwall.com/lists/oss-security/2012/12/02/3 | Mailing List |
|
http://www.openwall.com/lists/oss-security/2012/12/02/4 | Mailing List |
|
http://www.securitytracker.com/id?1027829 | Broken Link |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/23078 | 2012-12-02 | |
http://seclists.org/fulldisclosure/2012/Dec/7 | 2024-08-06 |
URL | Date | SRC |
---|---|---|
https://mariadb.atlassian.net/browse/MDEV-3910 | 2022-08-29 |
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2013-0772.html | 2022-08-29 | |
http://security.gentoo.org/glsa/glsa-201308-06.xml | 2022-08-29 | |
http://www.mandriva.com/security/advisories?name=MDVSA-2013:150 | 2022-08-29 | |
http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html | 2022-08-29 | |
https://bugzilla.redhat.com/show_bug.cgi?id=882607 | 2013-04-25 | |
https://access.redhat.com/security/cve/CVE-2012-5614 | 2013-04-25 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | >= 5.1.0 <= 5.1.67 Search vendor "Oracle" for product "Mysql" and version " >= 5.1.0 <= 5.1.67" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | >= 5.5.0 <= 5.5.29 Search vendor "Oracle" for product "Mysql" and version " >= 5.5.0 <= 5.5.29" | - |
Affected
| ||||||
Mariadb Search vendor "Mariadb" | Mariadb Search vendor "Mariadb" for product "Mariadb" | >= 5.5.0 < 5.5.30 Search vendor "Mariadb" for product "Mariadb" and version " >= 5.5.0 < 5.5.30" | - |
Affected
| ||||||
Mariadb Search vendor "Mariadb" | Mariadb Search vendor "Mariadb" for product "Mariadb" | >= 10.0.0 < 10.0.2 Search vendor "Mariadb" for product "Mariadb" and version " >= 10.0.0 < 10.0.2" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Desktop Search vendor "Redhat" for product "Enterprise Linux Desktop" | 6.0 Search vendor "Redhat" for product "Enterprise Linux Desktop" and version "6.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Eus Search vendor "Redhat" for product "Enterprise Linux Eus" | 6.4 Search vendor "Redhat" for product "Enterprise Linux Eus" and version "6.4" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Server Search vendor "Redhat" for product "Enterprise Linux Server" | 6.0 Search vendor "Redhat" for product "Enterprise Linux Server" and version "6.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Server Aus Search vendor "Redhat" for product "Enterprise Linux Server Aus" | 6.4 Search vendor "Redhat" for product "Enterprise Linux Server Aus" and version "6.4" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Workstation Search vendor "Redhat" for product "Enterprise Linux Workstation" | 6.0 Search vendor "Redhat" for product "Enterprise Linux Workstation" and version "6.0" | - |
Affected
|