CVE-2012-5612

Description

Heap-based buffer overflow in Oracle MySQL 5.5.19 and other versions through 5.5.28, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code, as demonstrated using certain variations of the (1) USE, (2) SHOW TABLES, (3) DESCRIBE, (4) SHOW FIELDS FROM, (5) SHOW COLUMNS FROM, (6) SHOW INDEX FROM, (7) CREATE TABLE, (8) DROP TABLE, (9) ALTER TABLE, (10) DELETE FROM, (11) UPDATE, and (12) SET PASSWORD commands.

Risk Information

Base Score
8.8
MODERATE
Vector
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
66.845

Associated Vulnerability

VulnerabilityOS Platform
Update MariaDB to 10.0.1Windows
Update MariaDB to 5.1.67Windows
Update MariaDB to 5.2.14Windows
Update MariaDB to 5.3.12Windows
Update MariaDB to 5.5.29 [2]Windows
Vulnerabilities CVE-2012-3163,CVE-2012-5611,CVE-2012-5612 are affected in Mysql 9.0Windows
Update MariaDB to 10.0.1 (For Linux)Linux
Update MariaDB to 5.1.67 (For Linux)Linux
Update MariaDB to 5.2.14 (For Linux)Linux
Update MariaDB to 5.3.12 (For Linux)Linux
Update MariaDB to 5.5.29 [2] (For Linux)Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234