Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2012-5611 | First vendor Publication | 2012-12-03 |
Vendor | Cve | Last vendor Modification | 2017-09-19 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:S/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 6.5 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Low |
Cvss Expoit Score | 8 | Authentication | Requires single instance |
Calculate full CVSS 2.0 Vectors scores |
Detail
Stack-based buffer overflow in the acl_get function in Oracle MySQL 5.5.19 and other versions through 5.5.28, and 5.1.53 and other versions through 5.1.66, and MariaDB 5.5.2.x before 5.5.28a, 5.3.x before 5.3.11, 5.2.x before 5.2.13 and 5.1.x before 5.1.66, allows remote authenticated users to execute arbitrary code via a long argument to the GRANT FILE command. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5611 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:16395 | |||
Oval ID: | oval:org.mitre.oval:def:16395 | ||
Title: | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server Privileges). Supported versions that are affected are 5.1.66 and earlier and 5.5.28 and earlier. Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution | ||
Description: | Stack-based buffer overflow in the acl_get function in Oracle MySQL 5.5.19 and other versions through 5.5.28, and 5.1.53 and other versions through 5.1.66, and MariaDB 5.5.2.x before 5.5.28a, 5.3.x before 5.3.11, 5.2.x before 5.2.13 and 5.1.x before 5.1.66, allows remote authenticated users to execute arbitrary code via a long argument to the GRANT FILE command. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2012-5611 | Version: | 6 |
Platform(s): | Microsoft Windows 2000 Microsoft Windows XP Microsoft Windows Vista Microsoft Windows 7 Microsoft Windows 8 Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows Server 2008 R2 Microsoft Windows Server 2012 | Product(s): | MySQL Server 5.1 MySQL Server 5.5 |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:17289 | |||
Oval ID: | oval:org.mitre.oval:def:17289 | ||
Title: | USN-1658-1 -- mysql-5.1, mysql-5.5, mysql-dfsg-5.1 vulnerability | ||
Description: | MySQL could be made to run programs if it received specially crafted network traffic from an authenticated user. | ||
Family: | unix | Class: | patch |
Reference(s): | USN-1658-1 CVE-2012-5611 | Version: | 7 |
Platform(s): | Ubuntu 12.10 Ubuntu 12.04 Ubuntu 11.10 Ubuntu 10.04 | Product(s): | mysql-5.5 mysql-5.1 mysql-dfsg-5.1 |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:18423 | |||
Oval ID: | oval:org.mitre.oval:def:18423 | ||
Title: | DSA-2581-1 mysql-5.1 - several | ||
Description: | Several issues have been discovered in the MySQL database server. The vulnerabilities are addressed by upgrading MySQL to a new upstream version, 5.1.66, which includes additional changes, such as performance improvements and corrections for data loss defects. These changes are described in the <a href="http://dev.mysql.com/doc/refman/5.1/en/news-5-1-66.html">MySQL release notes</a>. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-2581-1 CVE-2012-3150 CVE-2012-3158 CVE-2012-3160 CVE-2012-3163 CVE-2012-3166 CVE-2012-3167 CVE-2012-3173 CVE-2012-3177 CVE-2012-3180 CVE-2012-3197 CVE-2012-5611 | Version: | 7 |
Platform(s): | Debian GNU/Linux 6.0 Debian GNU/kFreeBSD 6.0 | Product(s): | mysql-5.1 |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:21022 | |||
Oval ID: | oval:org.mitre.oval:def:21022 | ||
Title: | RHSA-2013:0180: mysql security update (Important) | ||
Description: | Stack-based buffer overflow in the acl_get function in Oracle MySQL 5.5.19 and other versions through 5.5.28, and 5.1.53 and other versions through 5.1.66, and MariaDB 5.5.2.x before 5.5.28a, 5.3.x before 5.3.11, 5.2.x before 5.2.13 and 5.1.x before 5.1.66, allows remote authenticated users to execute arbitrary code via a long argument to the GRANT FILE command. | ||
Family: | unix | Class: | patch |
Reference(s): | RHSA-2013:0180-00 CESA-2013:0180 CVE-2012-2749 CVE-2012-5611 | Version: | 31 |
Platform(s): | Red Hat Enterprise Linux 5 CentOS Linux 5 | Product(s): | mysql |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:21528 | |||
Oval ID: | oval:org.mitre.oval:def:21528 | ||
Title: | RHSA-2012:1551: mysql security update (Important) | ||
Description: | Stack-based buffer overflow in the acl_get function in Oracle MySQL 5.5.19 and other versions through 5.5.28, and 5.1.53 and other versions through 5.1.66, and MariaDB 5.5.2.x before 5.5.28a, 5.3.x before 5.3.11, 5.2.x before 5.2.13 and 5.1.x before 5.1.66, allows remote authenticated users to execute arbitrary code via a long argument to the GRANT FILE command. | ||
Family: | unix | Class: | patch |
Reference(s): | RHSA-2012:1551-01 CESA-2012:1551 CVE-2012-5611 | Version: | 4 |
Platform(s): | Red Hat Enterprise Linux 6 CentOS Linux 6 | Product(s): | mysql |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:23326 | |||
Oval ID: | oval:org.mitre.oval:def:23326 | ||
Title: | ELSA-2013:0180: mysql security update (Important) | ||
Description: | Stack-based buffer overflow in the acl_get function in Oracle MySQL 5.5.19 and other versions through 5.5.28, and 5.1.53 and other versions through 5.1.66, and MariaDB 5.5.2.x before 5.5.28a, 5.3.x before 5.3.11, 5.2.x before 5.2.13 and 5.1.x before 5.1.66, allows remote authenticated users to execute arbitrary code via a long argument to the GRANT FILE command. | ||
Family: | unix | Class: | patch |
Reference(s): | ELSA-2013:0180-00 CVE-2012-2749 CVE-2012-5611 | Version: | 13 |
Platform(s): | Oracle Linux 5 | Product(s): | mysql |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:23921 | |||
Oval ID: | oval:org.mitre.oval:def:23921 | ||
Title: | ELSA-2012:1551: mysql security update (Important) | ||
Description: | Stack-based buffer overflow in the acl_get function in Oracle MySQL 5.5.19 and other versions through 5.5.28, and 5.1.53 and other versions through 5.1.66, and MariaDB 5.5.2.x before 5.5.28a, 5.3.x before 5.3.11, 5.2.x before 5.2.13 and 5.1.x before 5.1.66, allows remote authenticated users to execute arbitrary code via a long argument to the GRANT FILE command. | ||
Family: | unix | Class: | patch |
Reference(s): | ELSA-2012:1551-01 CVE-2012-5611 | Version: | 6 |
Platform(s): | Oracle Linux 6 | Product(s): | mysql |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:26706 | |||
Oval ID: | oval:org.mitre.oval:def:26706 | ||
Title: | DEPRECATED: ELSA-2012-1551 -- mysql security update (important) | ||
Description: | [5.1.66-2] - Add backported patch for CVE-2012-5611 Resolves: CVE-2012-5611 | ||
Family: | unix | Class: | patch |
Reference(s): | ELSA-2012-1551 CVE-2012-5611 | Version: | 4 |
Platform(s): | Oracle Linux 6 | Product(s): | mysql |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:27670 | |||
Oval ID: | oval:org.mitre.oval:def:27670 | ||
Title: | DEPRECATED: ELSA-2013-0180 -- mysql security update (important) | ||
Description: | [5.0.95-5] - Rebuild to fix wrong package tag Related: #892679 [5.0.95-4] - Add patches for CVE-2012-2122, CVE-2012-2749, CVE-2012-5611 Resolves: #892679 | ||
Family: | unix | Class: | patch |
Reference(s): | ELSA-2013-0180 CVE-2012-2749 CVE-2012-5611 | Version: | 4 |
Platform(s): | Oracle Linux 5 | Product(s): | mysql |
Definition Synopsis: | |||
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2013-09-18 | Name : Debian Security Advisory DSA 2581-1 (mysql-5.1 - several vulnerabilities) File : nvt/deb_2581_1.nasl |
2012-12-26 | Name : Fedora Update for mysql FEDORA-2012-19823 File : nvt/gb_fedora_2012_19823_mysql_fc16.nasl |
2012-12-18 | Name : Fedora Update for mysql FEDORA-2012-19833 File : nvt/gb_fedora_2012_19833_mysql_fc17.nasl |
2012-12-11 | Name : Ubuntu Update for mysql-5.5 USN-1658-1 File : nvt/gb_ubuntu_USN_1658_1.nasl |
2012-12-10 | Name : CentOS Update for mysql CESA-2012:1551 centos6 File : nvt/gb_CESA-2012_1551_mysql_centos6.nasl |
2012-12-10 | Name : RedHat Update for mysql RHSA-2012:1551-01 File : nvt/gb_RHSA-2012_1551-01_mysql.nasl |
2012-12-10 | Name : Mandriva Update for mysql MDVSA-2012:178 (mysql) File : nvt/gb_mandriva_MDVSA_2012_178.nasl |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | Oracle MySQL grant file long database name stack overflow attempt RuleID : 24897 - Revision : 5 - Type : SERVER-MYSQL |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2014-06-13 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2013-6.nasl - Type : ACT_GATHER_INFO |
2014-06-13 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2013-5.nasl - Type : ACT_GATHER_INFO |
2014-06-13 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2013-4.nasl - Type : ACT_GATHER_INFO |
2013-09-04 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2012-145.nasl - Type : ACT_GATHER_INFO |
2013-09-04 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2012-144.nasl - Type : ACT_GATHER_INFO |
2013-08-30 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201308-06.nasl - Type : ACT_GATHER_INFO |
2013-07-12 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2012-1551.nasl - Type : ACT_GATHER_INFO |
2013-07-12 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2013-0180.nasl - Type : ACT_GATHER_INFO |
2013-04-20 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2013-102.nasl - Type : ACT_GATHER_INFO |
2013-02-28 | Name : The remote database server is affected by multiple vulnerabilities. File : mariadb_5_1_67.nasl - Type : ACT_GATHER_INFO |
2013-02-28 | Name : The remote database server is affected by multiple vulnerabilities. File : mariadb_5_2_14.nasl - Type : ACT_GATHER_INFO |
2013-02-28 | Name : The remote database server is affected by multiple vulnerabilities. File : mariadb_5_3_12.nasl - Type : ACT_GATHER_INFO |
2013-02-28 | Name : The remote database server is affected by multiple vulnerabilities. File : mariadb_5_5_29.nasl - Type : ACT_GATHER_INFO |
2013-02-10 | Name : The remote SuSE 11 host is missing one or more security updates. File : suse_11_libmysqlclient-devel-121227.nasl - Type : ACT_GATHER_INFO |
2013-02-09 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2013-007.nasl - Type : ACT_GATHER_INFO |
2013-02-04 | Name : The remote FreeBSD host is missing one or more security-related updates. File : freebsd_pkg_8c773d7f6cbb11e2b242c8600054b392.nasl - Type : ACT_GATHER_INFO |
2013-01-24 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20130122_mysql_on_SL5_x.nasl - Type : ACT_GATHER_INFO |
2013-01-24 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2013-0180.nasl - Type : ACT_GATHER_INFO |
2013-01-23 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-1703-1.nasl - Type : ACT_GATHER_INFO |
2013-01-23 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2013-0180.nasl - Type : ACT_GATHER_INFO |
2013-01-18 | Name : The remote database server is affected by multiple vulnerabilities. File : mysql_5_1_67.nasl - Type : ACT_GATHER_INFO |
2013-01-18 | Name : The remote database server is affected by multiple vulnerabilities. File : mysql_5_5_29.nasl - Type : ACT_GATHER_INFO |
2013-01-14 | Name : The remote Fedora host is missing a security update. File : fedora_2012-19868.nasl - Type : ACT_GATHER_INFO |
2012-12-24 | Name : The remote Fedora host is missing a security update. File : fedora_2012-19823.nasl - Type : ACT_GATHER_INFO |
2012-12-17 | Name : The remote Fedora host is missing a security update. File : fedora_2012-19833.nasl - Type : ACT_GATHER_INFO |
2012-12-11 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-1658-1.nasl - Type : ACT_GATHER_INFO |
2012-12-11 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2012-1551.nasl - Type : ACT_GATHER_INFO |
2012-12-10 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2012-178.nasl - Type : ACT_GATHER_INFO |
2012-12-09 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2012-1551.nasl - Type : ACT_GATHER_INFO |
2012-12-08 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20121207_mysql_on_SL6_x.nasl - Type : ACT_GATHER_INFO |
2012-12-05 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-2581.nasl - Type : ACT_GATHER_INFO |
2012-12-04 | Name : The remote database server is affected by a buffer overflow vulnerability. File : mariadb_5_5_28a.nasl - Type : ACT_GATHER_INFO |
2012-12-04 | Name : The remote database server is affected by a buffer overflow vulnerability. File : mariadb_5_3_11.nasl - Type : ACT_GATHER_INFO |
2012-12-04 | Name : The remote database server is affected by a buffer overflow vulnerability. File : mariadb_5_2_13.nasl - Type : ACT_GATHER_INFO |
2012-12-04 | Name : The remote database server is affected by a buffer overflow vulnerability. File : mariadb_5_1_66.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2020-05-23 00:35:18 |
|
2017-09-19 09:25:37 |
|
2016-06-29 00:29:05 |
|
2016-04-26 22:30:17 |
|
2014-06-14 13:34:00 |
|
2014-02-21 13:22:31 |
|
2014-02-17 11:14:27 |
|
2014-01-19 21:28:57 |
|
2013-12-05 17:19:20 |
|
2013-11-04 21:24:25 |
|
2013-10-11 13:24:51 |
|
2013-09-20 17:21:17 |
|
2013-09-12 13:19:59 |
|
2013-08-29 13:20:27 |
|
2013-08-22 17:19:33 |
|
2013-05-10 22:49:48 |
|
2013-03-08 13:19:22 |
|
2013-02-08 13:20:12 |
|
2013-02-07 13:21:00 |
|
2013-01-18 13:19:26 |
|
2013-01-15 13:21:17 |
|
2012-12-19 13:25:58 |
|
2012-12-04 00:19:07 |
|
2012-12-03 17:23:38 |
|