CVE-2012-0882
published 2012-12-21CVE-2012-0882: Buffer overflow in yaSSL, as used in MySQL 5.5.20 and possibly other versions including 5.5.x before 5.5.22 and 5.1.x before 5.1.62, allows remote attackers to…
PriorityP342high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
5.30%
91.7th percentile
Buffer overflow in yaSSL, as used in MySQL 5.5.20 and possibly other versions including 5.5.x before 5.5.22 and 5.1.x before 5.1.62, allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by VulnDisco Pack Professional 9.17. NOTE: as of 20120224, this disclosure has no actionable information. However, because the module author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes. NOTE: due to lack of details, it is not clear whether this issue is a duplicate of CVE-2012-0492 or another CVE.
Affected
87 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w3hv-rp5r-hr2c: Buffer overflow in yaSSL, as used in MySQL 5
ghsa_unreviewed·2022-05-13·CVSS 2.1
CVE-2012-0882 [LOW] CWE-119 GHSA-w3hv-rp5r-hr2c: Buffer overflow in yaSSL, as used in MySQL 5
Buffer overflow in yaSSL, as used in MySQL 5.5.20 and possibly other versions including 5.5.x before 5.5.22 and 5.1.x before 5.1.62, allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by VulnDisco Pack Professional 9.17. NOTE: as of 20120224, this disclosure has no actionable information. However, because the module author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes. NOTE: due to lack of details, it is not clear whether this issue is a duplicate of CVE-2012-0492 or another CVE.
Red Hat
mysql: unspecified remote exploit (released with VulnDisco Pack Professional 9.17)
vendor_redhat·2012-02-09·CVSS 2.1
CVE-2012-0882 [LOW] mysql: unspecified remote exploit (released with VulnDisco Pack Professional 9.17)
mysql: unspecified remote exploit (released with VulnDisco Pack Professional 9.17)
Buffer overflow in yaSSL, as used in MySQL 5.5.20 and possibly other versions including 5.5.x before 5.5.22 and 5.1.x before 5.1.62, allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by VulnDisco Pack Professional 9.17. NOTE: as of 20120224, this disclosure has no actionable information. However, because the module author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes. NOTE: due to lack of details, it is not clear whether this issue is a duplicate of CVE-2012-0492 or another CVE.
Statement: We do not currently plan to fix this issue due to the lack of further
information about the flaw and its impact. If more information
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2012/02/24/2https://blogs.oracle.com/sunsecurity/entry/cve_2012_0882buffer_overflow_vulnerabilityhttps://bugzilla.redhat.com/show_bug.cgi?id=789141https://lists.immunityinc.com/pipermail/canvas/2012-February/000011.htmlhttps://lists.immunityinc.com/pipermail/canvas/2012-February/000014.htmlhttp://www.openwall.com/lists/oss-security/2012/02/24/2https://blogs.oracle.com/sunsecurity/entry/cve_2012_0882buffer_overflow_vulnerabilityhttps://bugzilla.redhat.com/show_bug.cgi?id=789141https://lists.immunityinc.com/pipermail/canvas/2012-February/000011.htmlhttps://lists.immunityinc.com/pipermail/canvas/2012-February/000014.html
2012-12-21
Published