CVE-2010-4177
published 2019-11-12CVE-2010-4177: mysql-gui-tools (mysql-query-browser and mysql-admin) before 5.0r14+openSUSE-2.3 exposes the password of a user connected to the MySQL server in clear text…
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.31%
23.7th percentile
mysql-gui-tools (mysql-query-browser and mysql-admin) before 5.0r14+openSUSE-2.3 exposes the password of a user connected to the MySQL server in clear text form via the list of running processes.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| mysql-gui-tools | mysql-gui-tools | — | — |
| oracle | mysql-gui-tools | < 5.0r14\+opensuse-2.3 | 5.0r14\+opensuse-2.3 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-4177 CVE-2010-4178 mysql-gui-tools various flaws [fedora-12]
bugzilla·2010-11-19·CVSS 5.5
CVE-2010-4177 [MEDIUM] CVE-2010-4177 CVE-2010-4178 mysql-gui-tools various flaws [fedora-12]
CVE-2010-4177 CVE-2010-4178 mysql-gui-tools various flaws [fedora-12]
fedora-12 tracking bug for mysql-gui-tools: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
Adding parent bug CVE-2010-4178
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=655015,655012
---
musql-gui-tools is dead package. It is not supported upstream many times and it is not Fedora start from 13. I do not want even see on it. Fedora 12 in few days reached EOL. So, I suggest close it.
---
Fedora 12 changed to end-of-life (EOL) status on 2010-12-02. Fedora 12 is
no longer maintained, which means that it
Bugzilla
CVE-2010-4177 mysql-gui-tools (mysql-query-browser): Clear text password in the process list after user's launch of mysql text console
bugzilla·2010-11-19·CVSS 5.5
CVE-2010-4177 [MEDIUM] CVE-2010-4177 mysql-gui-tools (mysql-query-browser): Clear text password in the process list after user's launch of mysql text console
CVE-2010-4177 mysql-gui-tools (mysql-query-browser): Clear text password in the process list after user's launch of mysql text console
Martin Drescher pointed out a deficiency in the way
mysql-query-browser launched MySQL Text Console
after user's MySQL connection to the MySQL server.
A local attacker could use this flaw to view the
password of the user, connected to the MySQL server,
in the clear text form via the list of running processes.
References:
[1] http://www.openwall.com/lists/oss-security/2010/11/16/6
[2] http://www.openwall.com/lists/oss-security/2010/11/18/2
Discussion:
This issue affects the version of the mysql-gui-tools package,
as shipped with Fedora release of 12.
Please fix.
---
Created mysql-gui-tools tracking bugs for this issue
Affects: fedora-12 [bug 655018]
http://www.securityfocus.com/bid/97959https://access.redhat.com/security/cve/cve-2010-4177https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=605542https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-4177https://security-tracker.debian.org/tracker/CVE-2010-4177https://www.openwall.com/lists/oss-security/2010/11/16/6http://www.securityfocus.com/bid/97959https://access.redhat.com/security/cve/cve-2010-4177https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=605542https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-4177https://security-tracker.debian.org/tracker/CVE-2010-4177https://www.openwall.com/lists/oss-security/2010/11/16/6
2019-11-12
Published