CVE-2012-1703
published 2012-05-03CVE-2012-1703: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.61 and earlier, and 5.5.21 and earlier, allows remote authenticated users to affect…
PriorityP429medium6.8CVSS 2.0
AVNACLAuSCNINAC
EPSS
3.74%
88.6th percentile
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.61 and earlier, and 5.5.21 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer, a different vulnerability than CVE-2012-1690.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mariadb | mariadb | >= 5.1.0 < 5.1.62 | 5.1.62 |
| mariadb | mariadb | >= 5.5.0 < 5.5.22 | 5.5.22 |
| oracle | mysql | 5.1.0 – 5.1.61 | — |
| oracle | mysql | 5.5.0 – 5.5.21 | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:C
cisa7.8HIGH
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6xhq-pwm3-5877: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5
ghsa_unreviewed·2022-05-13·CVSS 4.0
CVE-2012-1703 [MEDIUM] GHSA-6xhq-pwm3-5877: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.61 and earlier, and 5.5.21 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer, a different vulnerability than CVE-2012-1690.
GHSA
GHSA-3prr-gr45-j95v: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5
ghsa_unreviewed·2022-05-13·CVSS 6.8
CVE-2012-1690 [MEDIUM] GHSA-3prr-gr45-j95v: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.61 and earlier, and 5.5.21 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer, a different vulnerability than CVE-2012-1703.
CISA
Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability
cisa·2022-03-03·CVSS 7.8
CVE-2017-8540 [HIGH] CWE-119 Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability
Vulnerability: Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability
Affected: Microsoft Malware Protection Engine
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability".
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2017-8540
Remediation Due Date: 2022-03-24
Red Hat
mysql: unspecified DoS vulnerability related to Server Optimizer (CPU Apr 2012)
vendor_redhat·2012-04-17·CVSS 4.0
CVE-2012-1690 [MEDIUM] mysql: unspecified DoS vulnerability related to Server Optimizer (CPU Apr 2012)
mysql: unspecified DoS vulnerability related to Server Optimizer (CPU Apr 2012)
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.61 and earlier, and 5.5.21 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer, a different vulnerability than CVE-2012-1703.
Package: mysql (Red Hat Enterprise Linux 5) - Under investigation
Red Hat
mysql: unspecified DoS vulnerability related to Server Optimizer (CPU Apr 2012)
vendor_redhat·2012-04-17·CVSS 4.0
CVE-2012-1703 [MEDIUM] mysql: unspecified DoS vulnerability related to Server Optimizer (CPU Apr 2012)
mysql: unspecified DoS vulnerability related to Server Optimizer (CPU Apr 2012)
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.61 and earlier, and 5.5.21 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer, a different vulnerability than CVE-2012-1690.
Statement: On Red Hat Enterprise Linux 5.10, new MySQL 5.5 packages are available which are not vulnerable to this issue. Future updates for MySQL 5.0 will no longer be made available (mysql-5.0.* and related packages); security advisories will be provided only for MySQL 5.5. Please refer to https://rhn.redhat.com/errata/RHEA-2013-1330.html for further information.
Package: mysql (Red Hat Enterprise Linux 5) - Under investigation
No detection rules found.
No public exploits indexed.
Bugzilla
mysql: Oracle CPU April 2012
bugzilla·2012-06-15·CVSS 4.0
[MEDIUM] mysql: Oracle CPU April 2012
mysql: Oracle CPU April 2012
This bug is for Oracle Critical Patch Update Advisory - April 2012 that lists 6 MySQL flaws:
http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html
Fixes for these issues are included in versions 5.1.62 and 5.5.22.
Previous CPU for MySQL was released in January 2012:
http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html
Security flaws in Jan 2012 CPU were fixed in versions 5.0.95, 5.1.61, and 5.5.20 (MySQL version 5.0.x reached end of life in between Jan and Apr CPUs). Therefore, following versions were released in between the two CPUs:
http://dev.mysql.com/doc/refman/5.1/en/news-5-1-62.html
http://dev.mysql.com/doc/refman/5.5/en/news-5-5-21.html
http://dev.mysql.com/doc/refman/5.5/en/news-5-5-22.html
The aim here is
Bugzilla
CVE-2012-1703 mysql: unspecified DoS vulnerability related to Server Optimizer (CPU Apr 2012)
bugzilla·2012-04-19·CVSS 6.8
CVE-2012-1703 [MEDIUM] CVE-2012-1703 mysql: unspecified DoS vulnerability related to Server Optimizer (CPU Apr 2012)
CVE-2012-1703 mysql: unspecified DoS vulnerability related to Server Optimizer (CPU Apr 2012)
Unspecified vulnerability in the server optimizer subcomponent of the Oracle MySQL server could allow authenticated database users to cause frequently repeatable crash of the MySQL server or, potentially, underlying operating system hang via multiple protocols.
Upstream announced, supported MySQL server versions, vulnerable to this flaw:
5.1.61 and earlier and 5.5.21 and earlier
References:
[1] http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html#AppendixMSQL
[2] http://www.oracle.com/technetwork/topics/security/cpuapr2012verbose-366316.html#Oracle%20MySQL
Discussion:
Is there a timeframe when this bug will be fixed?
---
This issue has been addressed in following product
http://rhn.redhat.com/errata/RHSA-2012-1462.htmlhttp://secunia.com/advisories/48890http://secunia.com/advisories/49179http://secunia.com/advisories/51309http://secunia.com/advisories/53372http://security.gentoo.org/glsa/glsa-201308-06.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2013:150http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.htmlhttp://www.securityfocus.com/bid/53058http://www.securitytracker.com/id?1026934http://rhn.redhat.com/errata/RHSA-2012-1462.htmlhttp://secunia.com/advisories/48890http://secunia.com/advisories/49179http://secunia.com/advisories/51309http://secunia.com/advisories/53372http://security.gentoo.org/glsa/glsa-201308-06.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2013:150http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.htmlhttp://www.securityfocus.com/bid/53058http://www.securitytracker.com/id?1026934
2012-05-03
Published