Уязвимость CVE-2012-5611: Информация

Описание

Stack-based buffer overflow in the acl_get function in Oracle MySQL 5.5.19 and other versions through 5.5.28, and 5.1.53 and other versions through 5.1.66, and MariaDB 5.5.2.x before 5.5.28a, 5.3.x before 5.3.11, 5.2.x before 5.2.13 and 5.1.x before 5.1.66, allows remote authenticated users to execute arbitrary code via a long argument to the GRANT FILE command.

Важность: MEDIUM (6,5)

Опубликовано: 3 декабря 2012 г.
Изменено: 17 мая 2024 г.
Идентификатор типа ошибки: CWE-119

Ссылки на рекомендации, решения и инструменты

Ссылка
Ресурс
20121201 MySQL (Linux) Stack based buffer overrun PoC Zeroday
  • Mailing List
  • Third Party Advisory
23075
  • Third Party Advisory
  • VDB Entry
[oss-security] 20121202 Re: Re: [Full-disclosure] MySQL (Linux) Stack based buffer overrun PoC Zeroday
  • Mailing List
  • Third Party Advisory
[oss-security] 20121202 Re: Re: [Full-disclosure] MySQL (Linux) Stack based buffer overrun PoC Zeroday
  • Mailing List
  • Third Party Advisory
RHSA-2012:1551
  • Third Party Advisory
USN-1658-1
  • Third Party Advisory
openSUSE-SU-2013:0013
  • Mailing List
  • Third Party Advisory
http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html
  • Third Party Advisory
RHSA-2013:0180
  • Third Party Advisory
USN-1703-1
  • Third Party Advisory
openSUSE-SU-2013:0014
  • Mailing List
  • Third Party Advisory
openSUSE-SU-2013:0011
  • Mailing List
  • Third Party Advisory
openSUSE-SU-2013:0135
  • Mailing List
  • Third Party Advisory
openSUSE-SU-2013:0156
  • Mailing List
  • Third Party Advisory
DSA-2581
  • Third Party Advisory
SUSE-SU-2013:0262
  • Mailing List
  • Third Party Advisory
https://kb.askmonty.org/en/mariadb-5528a-release-notes/
  • Third Party Advisory
51443
  • Broken Link
https://kb.askmonty.org/en/mariadb-5311-release-notes/
  • Third Party Advisory
https://kb.askmonty.org/en/mariadb-5213-release-notes/
  • Third Party Advisory
https://kb.askmonty.org/en/mariadb-5166-release-notes/
  • Third Party Advisory
openSUSE-SU-2013:1412
  • Mailing List
  • Third Party Advisory
MDVSA-2013:150
  • Third Party Advisory
GLSA-201308-06
  • Third Party Advisory
MDVSA-2013:102
  • Third Party Advisory
53372
  • Broken Link
oval:org.mitre.oval:def:16395
  • Third Party Advisory
    1. Конфигурация 1

      cpe:2.3:a:mariadb:mariadb:5.1.41:*:*:*:*:*:*:*

      cpe:2.3:a:mariadb:mariadb:5.1.42:*:*:*:*:*:*:*

      cpe:2.3:a:mariadb:mariadb:5.1.44:*:*:*:*:*:*:*

      cpe:2.3:a:mariadb:mariadb:5.1.47:*:*:*:*:*:*:*

      cpe:2.3:a:mariadb:mariadb:5.1.49:*:*:*:*:*:*:*

      cpe:2.3:a:mariadb:mariadb:5.1.50:*:*:*:*:*:*:*

      cpe:2.3:a:mariadb:mariadb:5.1.51:*:*:*:*:*:*:*

      cpe:2.3:a:mariadb:mariadb:5.1.53:*:*:*:*:*:*:*

      cpe:2.3:a:mariadb:mariadb:5.1.55:*:*:*:*:*:*:*

      cpe:2.3:a:mariadb:mariadb:5.1.60:*:*:*:*:*:*:*

      cpe:2.3:a:mariadb:mariadb:5.1.61:*:*:*:*:*:*:*

      cpe:2.3:a:mariadb:mariadb:5.1.62:*:*:*:*:*:*:*

      cpe:2.3:a:mariadb:mariadb:5.2.0:*:*:*:*:*:*:*

      cpe:2.3:a:mariadb:mariadb:5.2.1:*:*:*:*:*:*:*

      cpe:2.3:a:mariadb:mariadb:5.2.2:*:*:*:*:*:*:*

      cpe:2.3:a:mariadb:mariadb:5.2.3:*:*:*:*:*:*:*

      cpe:2.3:a:mariadb:mariadb:5.2.4:*:*:*:*:*:*:*

      cpe:2.3:a:mariadb:mariadb:5.2.5:*:*:*:*:*:*:*

      cpe:2.3:a:mariadb:mariadb:5.2.6:*:*:*:*:*:*:*

      cpe:2.3:a:mariadb:mariadb:5.2.7:*:*:*:*:*:*:*

      cpe:2.3:a:mariadb:mariadb:5.2.8:*:*:*:*:*:*:*

      cpe:2.3:a:mariadb:mariadb:5.2.9:*:*:*:*:*:*:*

      cpe:2.3:a:mariadb:mariadb:5.2.10:*:*:*:*:*:*:*

      cpe:2.3:a:mariadb:mariadb:5.2.11:*:*:*:*:*:*:*

      cpe:2.3:a:mariadb:mariadb:5.2.12:*:*:*:*:*:*:*

      cpe:2.3:a:mariadb:mariadb:5.3.0:*:*:*:*:*:*:*

      cpe:2.3:a:mariadb:mariadb:5.3.1:*:*:*:*:*:*:*

      cpe:2.3:a:mariadb:mariadb:5.3.2:*:*:*:*:*:*:*

      cpe:2.3:a:mariadb:mariadb:5.3.3:*:*:*:*:*:*:*

      cpe:2.3:a:mariadb:mariadb:5.3.4:*:*:*:*:*:*:*

      cpe:2.3:a:mariadb:mariadb:5.3.5:*:*:*:*:*:*:*

      cpe:2.3:a:mariadb:mariadb:5.3.6:*:*:*:*:*:*:*

      cpe:2.3:a:mariadb:mariadb:5.3.7:*:*:*:*:*:*:*

      cpe:2.3:a:mariadb:mariadb:5.3.8:*:*:*:*:*:*:*

      cpe:2.3:a:mariadb:mariadb:5.3.9:*:*:*:*:*:*:*

      cpe:2.3:a:mariadb:mariadb:5.3.10:*:*:*:*:*:*:*

      cpe:2.3:a:mariadb:mariadb:5.5.20:*:*:*:*:*:*:*

      cpe:2.3:a:mariadb:mariadb:5.5.21:*:*:*:*:*:*:*

      cpe:2.3:a:mariadb:mariadb:5.5.22:*:*:*:*:*:*:*

      cpe:2.3:a:mariadb:mariadb:5.5.23:*:*:*:*:*:*:*

      cpe:2.3:a:mariadb:mariadb:5.5.24:*:*:*:*:*:*:*

      cpe:2.3:a:mariadb:mariadb:5.5.25:*:*:*:*:*:*:*

      cpe:2.3:a:mariadb:mariadb:5.5.27:*:*:*:*:*:*:*

      cpe:2.3:a:mariadb:mariadb:5.5.28:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:mysql:5.1.53:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:mysql:5.5.19:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*