CVE-2012-1690
published 2012-05-03CVE-2012-1690: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.61 and earlier, and 5.5.21 and earlier, allows remote authenticated users to affect…
PriorityP417medium4CVSS 2.0
AVNACLAuSCNINAP
EPSS
3.31%
87.2th percentile
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.61 and earlier, and 5.5.21 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer, a different vulnerability than CVE-2012-1703.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mariadb | mariadb | >= 5.1.0 < 5.1.62 | 5.1.62 |
| mariadb | mariadb | >= 5.5.0 < 5.5.22 | 5.5.22 |
| oracle | mysql | 5.1.0 – 5.1.61 | — |
| oracle | mysql | 5.5.0 – 5.5.21 | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6xhq-pwm3-5877: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5
ghsa_unreviewed·2022-05-13·CVSS 4.0
CVE-2012-1703 [MEDIUM] GHSA-6xhq-pwm3-5877: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.61 and earlier, and 5.5.21 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer, a different vulnerability than CVE-2012-1690.
GHSA
GHSA-3prr-gr45-j95v: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5
ghsa_unreviewed·2022-05-13·CVSS 6.8
CVE-2012-1690 [MEDIUM] GHSA-3prr-gr45-j95v: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.61 and earlier, and 5.5.21 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer, a different vulnerability than CVE-2012-1703.
Red Hat
mysql: unspecified DoS vulnerability related to Server Optimizer (CPU Apr 2012)
vendor_redhat·2012-04-17·CVSS 4.0
CVE-2012-1690 [MEDIUM] mysql: unspecified DoS vulnerability related to Server Optimizer (CPU Apr 2012)
mysql: unspecified DoS vulnerability related to Server Optimizer (CPU Apr 2012)
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.61 and earlier, and 5.5.21 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer, a different vulnerability than CVE-2012-1703.
Package: mysql (Red Hat Enterprise Linux 5) - Under investigation
Red Hat
mysql: unspecified DoS vulnerability related to Server Optimizer (CPU Apr 2012)
vendor_redhat·2012-04-17·CVSS 4.0
CVE-2012-1703 [MEDIUM] mysql: unspecified DoS vulnerability related to Server Optimizer (CPU Apr 2012)
mysql: unspecified DoS vulnerability related to Server Optimizer (CPU Apr 2012)
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.61 and earlier, and 5.5.21 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer, a different vulnerability than CVE-2012-1690.
Statement: On Red Hat Enterprise Linux 5.10, new MySQL 5.5 packages are available which are not vulnerable to this issue. Future updates for MySQL 5.0 will no longer be made available (mysql-5.0.* and related packages); security advisories will be provided only for MySQL 5.5. Please refer to https://rhn.redhat.com/errata/RHEA-2013-1330.html for further information.
Package: mysql (Red Hat Enterprise Linux 5) - Under investigation
No detection rules found.
No public exploits indexed.
Bugzilla
mysql: Oracle CPU April 2012
bugzilla·2012-06-15·CVSS 4.0
[MEDIUM] mysql: Oracle CPU April 2012
mysql: Oracle CPU April 2012
This bug is for Oracle Critical Patch Update Advisory - April 2012 that lists 6 MySQL flaws:
http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html
Fixes for these issues are included in versions 5.1.62 and 5.5.22.
Previous CPU for MySQL was released in January 2012:
http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html
Security flaws in Jan 2012 CPU were fixed in versions 5.0.95, 5.1.61, and 5.5.20 (MySQL version 5.0.x reached end of life in between Jan and Apr CPUs). Therefore, following versions were released in between the two CPUs:
http://dev.mysql.com/doc/refman/5.1/en/news-5-1-62.html
http://dev.mysql.com/doc/refman/5.5/en/news-5-5-21.html
http://dev.mysql.com/doc/refman/5.5/en/news-5-5-22.html
The aim here is
Bugzilla
CVE-2012-1690 mysql: unspecified DoS vulnerability related to Server Optimizer (CPU Apr 2012)
bugzilla·2012-04-19·CVSS 4.0
CVE-2012-1690 [MEDIUM] CVE-2012-1690 mysql: unspecified DoS vulnerability related to Server Optimizer (CPU Apr 2012)
CVE-2012-1690 mysql: unspecified DoS vulnerability related to Server Optimizer (CPU Apr 2012)
Unspecified vulnerability in the server optimizer subcomponent of the Oracle MySQL server could allow authenticated database users to cause a hang or frequently repeatable crash of the MySQL server via multiple protocols.
Upstream announced, supported MySQL server versions, vulnerable to this flaw:
5.1.61 and earlier and 5.5.21 and earlier
References:
[1] http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html#AppendixMSQL
[2] http://www.oracle.com/technetwork/topics/security/cpuapr2012verbose-366316.html#Oracle%20MySQL
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2012:1462 https://rhn.redhat.com/errata/RHSA-2012-1462.
http://rhn.redhat.com/errata/RHSA-2012-1462.htmlhttp://secunia.com/advisories/48890http://secunia.com/advisories/49179http://secunia.com/advisories/51309http://secunia.com/advisories/53372http://security.gentoo.org/glsa/glsa-201308-06.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2013:150http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.htmlhttp://www.securityfocus.com/bid/53074http://www.securitytracker.com/id?1026934http://rhn.redhat.com/errata/RHSA-2012-1462.htmlhttp://secunia.com/advisories/48890http://secunia.com/advisories/49179http://secunia.com/advisories/51309http://secunia.com/advisories/53372http://security.gentoo.org/glsa/glsa-201308-06.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2013:150http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.htmlhttp://www.securityfocus.com/bid/53074http://www.securitytracker.com/id?1026934
2012-05-03
Published