CVE-2012-1688
published 2012-05-03CVE-2012-1688: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.61 and earlier, and 5.5.21 and earlier, allows remote authenticated users to affect…
PriorityP417medium4CVSS 2.0
AVNACLAuSCNINAP
EPSS
3.52%
87.9th percentile
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.61 and earlier, and 5.5.21 and earlier, allows remote authenticated users to affect availability, related to Server DML.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mariadb | mariadb | >= 5.1.0 < 5.1.62 | 5.1.62 |
| mariadb | mariadb | >= 5.5.0 < 5.5.22 | 5.5.22 |
| oracle | mysql | 5.1.0 – 5.1.61 | — |
| oracle | mysql | 5.5.0 – 5.5.21 | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
mysql: unspecified DoS vulnerability related to DML (CPU Apr 2012)
vendor_redhat·2012-04-17·CVSS 4.0
CVE-2012-1688 [MEDIUM] mysql: unspecified DoS vulnerability related to DML (CPU Apr 2012)
mysql: unspecified DoS vulnerability related to DML (CPU Apr 2012)
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.61 and earlier, and 5.5.21 and earlier, allows remote authenticated users to affect availability, related to Server DML.
Package: mysql (Red Hat Enterprise Linux 5) - Under investigation
GHSA
GHSA-rghf-5q3x-c6vw: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5
ghsa_unreviewed·2022-05-13
CVE-2012-1688 [MEDIUM] GHSA-rghf-5q3x-c6vw: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.61 and earlier, and 5.5.21 and earlier, allows remote authenticated users to affect availability, related to Server DML.
No detection rules found.
No public exploits indexed.
Bugzilla
mysql: Oracle CPU April 2012
bugzilla·2012-06-15·CVSS 4.0
[MEDIUM] mysql: Oracle CPU April 2012
mysql: Oracle CPU April 2012
This bug is for Oracle Critical Patch Update Advisory - April 2012 that lists 6 MySQL flaws:
http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html
Fixes for these issues are included in versions 5.1.62 and 5.5.22.
Previous CPU for MySQL was released in January 2012:
http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html
Security flaws in Jan 2012 CPU were fixed in versions 5.0.95, 5.1.61, and 5.5.20 (MySQL version 5.0.x reached end of life in between Jan and Apr CPUs). Therefore, following versions were released in between the two CPUs:
http://dev.mysql.com/doc/refman/5.1/en/news-5-1-62.html
http://dev.mysql.com/doc/refman/5.5/en/news-5-5-21.html
http://dev.mysql.com/doc/refman/5.5/en/news-5-5-22.html
The aim here is
Bugzilla
CVE-2012-1688 mysql: unspecified DoS vulnerability related to DML (CPU Apr 2012)
bugzilla·2012-04-19·CVSS 4.0
CVE-2012-1688 [MEDIUM] CVE-2012-1688 mysql: unspecified DoS vulnerability related to DML (CPU Apr 2012)
CVE-2012-1688 mysql: unspecified DoS vulnerability related to DML (CPU Apr 2012)
Unspecified vulnerability in the DML subcomponent of the Oracle MySQL server could allow authenticated database users to cause a hang or frequently repeatable crash of the MySQL server via multiple protocols.
Upstream announced, supported MySQL server versions, vulnerable to this flaw:
5.1.61 and earlier and 5.5.21 and earlier
References:
[1] http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html#AppendixMSQL
[2] http://www.oracle.com/technetwork/topics/security/cpuapr2012verbose-366316.html#Oracle%20MySQL
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2012:1462 https://rhn.redhat.com/errata/RHSA-2012-1462.html
http://rhn.redhat.com/errata/RHSA-2012-1462.htmlhttp://secunia.com/advisories/48890http://secunia.com/advisories/49179http://secunia.com/advisories/51309http://secunia.com/advisories/53372http://security.gentoo.org/glsa/glsa-201308-06.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2013:150http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.htmlhttp://www.securityfocus.com/bid/53067http://www.securitytracker.com/id?1026934http://rhn.redhat.com/errata/RHSA-2012-1462.htmlhttp://secunia.com/advisories/48890http://secunia.com/advisories/49179http://secunia.com/advisories/51309http://secunia.com/advisories/53372http://security.gentoo.org/glsa/glsa-201308-06.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2013:150http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.htmlhttp://www.securityfocus.com/bid/53067http://www.securitytracker.com/id?1026934
2012-05-03
Published