CVE-2012-5614
MySQL - Denial of Service (PoC)
Severity Score
4.0
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
2
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Oracle MySQL 5.1.67 and earlier and 5.5.29 and earlier, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a denial of service (mysqld crash) via a SELECT command with an UpdateXML command containing XML with a large number of unique, nested elements.
MySQL v5.5.19 y posiblemente otras versiones, y MariaDB v5.5.28a y posiblemente otras versiones, permiten a usuarios remotos autenticados provocar una denegación de servicio (caída de mysqld) a través de un comando SELECT con un comando updateXML que contiene XML con un gran número de elementos anidados "unique".
Oracle MySQL version 5.5.19-log on SuSE Linux suffers from a denial of service vulnerability.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2012-10-24 CVE Reserved
- 2012-12-02 First Exploit
- 2012-12-03 CVE Published
- 2024-07-03 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (13)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/53372 | Not Applicable | |
http://www.openwall.com/lists/oss-security/2012/12/02/3 | Mailing List | |
http://www.openwall.com/lists/oss-security/2012/12/02/4 | Mailing List | |
http://www.securitytracker.com/id?1027829 | Broken Link |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/23078 | 2012-12-02 | |
http://seclists.org/fulldisclosure/2012/Dec/7 | 2024-08-06 |
URL | Date | SRC |
---|---|---|
https://mariadb.atlassian.net/browse/MDEV-3910 | 2022-08-29 |
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2013-0772.html | 2022-08-29 | |
http://security.gentoo.org/glsa/glsa-201308-06.xml | 2022-08-29 | |
http://www.mandriva.com/security/advisories?name=MDVSA-2013:150 | 2022-08-29 | |
http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html | 2022-08-29 | |
https://bugzilla.redhat.com/show_bug.cgi?id=882607 | 2013-04-25 | |
https://access.redhat.com/security/cve/CVE-2012-5614 | 2013-04-25 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | >= 5.1.0 <= 5.1.67 Search vendor "Oracle" for product "Mysql" and version " >= 5.1.0 <= 5.1.67" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Mysql Search vendor "Oracle" for product "Mysql" | >= 5.5.0 <= 5.5.29 Search vendor "Oracle" for product "Mysql" and version " >= 5.5.0 <= 5.5.29" | - |
Affected
| ||||||
Mariadb Search vendor "Mariadb" | Mariadb Search vendor "Mariadb" for product "Mariadb" | >= 5.5.0 < 5.5.30 Search vendor "Mariadb" for product "Mariadb" and version " >= 5.5.0 < 5.5.30" | - |
Affected
| ||||||
Mariadb Search vendor "Mariadb" | Mariadb Search vendor "Mariadb" for product "Mariadb" | >= 10.0.0 < 10.0.2 Search vendor "Mariadb" for product "Mariadb" and version " >= 10.0.0 < 10.0.2" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Desktop Search vendor "Redhat" for product "Enterprise Linux Desktop" | 6.0 Search vendor "Redhat" for product "Enterprise Linux Desktop" and version "6.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Eus Search vendor "Redhat" for product "Enterprise Linux Eus" | 6.4 Search vendor "Redhat" for product "Enterprise Linux Eus" and version "6.4" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Server Search vendor "Redhat" for product "Enterprise Linux Server" | 6.0 Search vendor "Redhat" for product "Enterprise Linux Server" and version "6.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Server Aus Search vendor "Redhat" for product "Enterprise Linux Server Aus" | 6.4 Search vendor "Redhat" for product "Enterprise Linux Server Aus" and version "6.4" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Workstation Search vendor "Redhat" for product "Enterprise Linux Workstation" | 6.0 Search vendor "Redhat" for product "Enterprise Linux Workstation" and version "6.0" | - |
Affected
|