CVE-2012-5614

Description

Oracle MySQL 5.1.67 and earlier and 5.5.29 and earlier, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a denial of service (mysqld crash) via a SELECT command with an UpdateXML command containing XML with a large number of unique, nested elements.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
8.515

Associated Vulnerability

VulnerabilityOS Platform
Update MariaDB to 10.0.2Windows
Update MariaDB to 5.5.30Windows
Multiple vulnerabilities are affected in Mysql 4.0Windows
Update MariaDB to 10.0.2 (For Linux)Linux
Update MariaDB to 5.5.30 (For Linux)Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234