CVE-2012-1689
published 2012-07-17CVE-2012-1689: Unspecified vulnerability in Oracle MySQL Server 5.1.62 and earlier, and 5.5.22 and earlier, allows remote authenticated users to affect availability via…
PriorityP419medium4CVSS 2.0
AVNACLAuSCNINAP
EPSS
3.70%
88.5th percentile
Unspecified vulnerability in Oracle MySQL Server 5.1.62 and earlier, and 5.5.22 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| mariadb | mariadb | >= 5.1.0 < 5.1.66 | 5.1.66 |
| mariadb | mariadb | >= 5.5.0 < 5.5.23 | 5.5.23 |
| mariadb | mariadb | 5.5.0 – 5.5.23 | — |
| oracle | mysql | 5.1.0 – 5.1.62 | — |
| oracle | mysql | >= 5.5.0 < 5.5.23 | 5.5.23 |
| oracle | mysql | 5.5.0 – 5.5.22 | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-42wg-x9j5-37hp: Unspecified vulnerability in MySQL 5
ghsa_unreviewed·2022-05-13·CVSS 4.0
CVE-2012-2750 [MEDIUM] GHSA-42wg-x9j5-37hp: Unspecified vulnerability in MySQL 5
Unspecified vulnerability in MySQL 5.5.x before 5.5.23 has unknown impact and attack vectors related to a "Security Fix", aka Bug #59533. NOTE: this might be a duplicate of CVE-2012-1689, but as of 20120816, Oracle has not commented on this possibility.
GHSA
GHSA-wgcw-36qc-jvj2: Unspecified vulnerability in Oracle MySQL Server 5
ghsa_unreviewed·2022-05-13
CVE-2012-1689 [MEDIUM] GHSA-wgcw-36qc-jvj2: Unspecified vulnerability in Oracle MySQL Server 5
Unspecified vulnerability in Oracle MySQL Server 5.1.62 and earlier, and 5.5.22 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
Red Hat
mysql: unspecified DoS vulnerability related to Server Optimizer (CPU Jul 2012)
vendor_redhat·2012-07-18·CVSS 4.0
CVE-2012-1689 [MEDIUM] mysql: unspecified DoS vulnerability related to Server Optimizer (CPU Jul 2012)
mysql: unspecified DoS vulnerability related to Server Optimizer (CPU Jul 2012)
Unspecified vulnerability in Oracle MySQL Server 5.1.62 and earlier, and 5.5.22 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
Package: mysql (Red Hat Enterprise Linux 5) - Under investigation
Red Hat
mysql: unspecified flaw related to Optimizer
vendor_redhat·2012-04-12·CVSS 4.0
CVE-2012-2750 [MEDIUM] mysql: unspecified flaw related to Optimizer
mysql: unspecified flaw related to Optimizer
Unspecified vulnerability in MySQL 5.5.x before 5.5.23 has unknown impact and attack vectors related to a "Security Fix", aka Bug #59533. NOTE: this might be a duplicate of CVE-2012-1689, but as of 20120816, Oracle has not commented on this possibility.
Package: mysql (Red Hat Enterprise Linux 5) - Under investigation
Package: mysql (Red Hat Enterprise Linux 6) - Affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-1689 mysql: unspecified DoS vulnerability related to Server Optimizer (CPU Jul 2012)
bugzilla·2012-07-18·CVSS 4.0
CVE-2012-1689 [MEDIUM] CVE-2012-1689 mysql: unspecified DoS vulnerability related to Server Optimizer (CPU Jul 2012)
CVE-2012-1689 mysql: unspecified DoS vulnerability related to Server Optimizer (CPU Jul 2012)
Common Vulnerabilities and Exposures assigned an identifier CVE-2012-1689 to
the following vulnerability:
Name: CVE-2012-1689
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1689
Assigned: 20120316
Reference: http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.html
Unspecified vulnerability in Oracle MySQL Server 5.1.62 and earlier,
and 5.5.22 and earlier, allows remote authenticated users to affect
availability via unknown vectors related to Server Optimizer.
Discussion:
This CVE may be a full or partial duplicate of CVE-2012-2750 (bug #833742). Upstream is unlikely to provide any further info, so we can't be sure.
---
A possible candidate for this issue is the
Bugzilla
CVE-2012-2750 mysql: unspecified flaw related to Optimizer
bugzilla·2012-06-20·CVSS 4.0
CVE-2012-2750 [MEDIUM] CVE-2012-2750 mysql: unspecified flaw related to Optimizer
CVE-2012-2750 mysql: unspecified flaw related to Optimizer
MySQL version 5.5.23 releases notes mention following security fix:
* Security Fix: Bug #59533 was fixed.
http://dev.mysql.com/doc/refman/5.5/en/news-5-5-23.html
Upstream bug is currently private and there's no additional info currently available for this issue. The bug is not referenced by any commit in the upstream bazaar repositories.
http://bugs.mysql.com/bug.php?id=59533
Discussion:
There's still no information available for this issue even after the released of Oracle July 2012 CPU:
http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.html
Of the CVEs listed in the CPU, there's only one listed as fixed in 5.5.23:
CVE-2012-1689 Server Optimizer 4.0/AV:N/AC:L/Au:S/C:N/I:N/A:P+
CVE-2012-1689 is also list
http://osvdb.org/83980http://rhn.redhat.com/errata/RHSA-2012-1462.htmlhttp://secunia.com/advisories/51309http://secunia.com/advisories/53372http://security.gentoo.org/glsa/glsa-201308-06.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2013:150http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.htmlhttp://www.securityfocus.com/bid/54547http://www.securitytracker.com/id?1027263https://exchange.xforce.ibmcloud.com/vulnerabilities/77065http://osvdb.org/83980http://rhn.redhat.com/errata/RHSA-2012-1462.htmlhttp://secunia.com/advisories/51309http://secunia.com/advisories/53372http://security.gentoo.org/glsa/glsa-201308-06.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2013:150http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.htmlhttp://www.securityfocus.com/bid/54547http://www.securitytracker.com/id?1027263https://exchange.xforce.ibmcloud.com/vulnerabilities/77065
2012-07-17
Published