CVE-2012-2102
published 2012-08-17CVE-2012-2102: MySQL 5.1.x before 5.1.62 and 5.5.x before 5.5.22 allows remote authenticated users to cause a denial of service (assertion failure and mysqld abort) by…
PriorityP412low3.5CVSS 2.0
AVNACMAuSCNINAP
EPSS
2.09%
79.6th percentile
MySQL 5.1.x before 5.1.62 and 5.5.x before 5.5.22 allows remote authenticated users to cause a denial of service (assertion failure and mysqld abort) by deleting a record and using HANDLER READ NEXT.
Affected
87 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:N/A:P
vendor_redhat3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
mysql: Server crash on HANDLER READ NEXT after DELETE
vendor_redhat·2012-03-21·CVSS 3.5
CVE-2012-2102 [LOW] mysql: Server crash on HANDLER READ NEXT after DELETE
mysql: Server crash on HANDLER READ NEXT after DELETE
MySQL 5.1.x before 5.1.62 and 5.5.x before 5.5.22 allows remote authenticated users to cause a denial of service (assertion failure and mysqld abort) by deleting a record and using HANDLER READ NEXT.
Statement: This issue did not affect the versions of mysql as shipped with Red Hat Enterprise Linux 5.
Package: mysql (Red Hat Enterprise Linux 5) - Not affected
GHSA
GHSA-jwxg-6x5j-r846: MySQL 5
ghsa_unreviewed·2022-05-13
CVE-2012-2102 [LOW] CWE-119 GHSA-jwxg-6x5j-r846: MySQL 5
MySQL 5.1.x before 5.1.62 and 5.5.x before 5.5.22 allows remote authenticated users to cause a denial of service (assertion failure and mysqld abort) by deleting a record and using HANDLER READ NEXT.
No detection rules found.
No public exploits indexed.
Bugzilla
mysql: Oracle CPU April 2012
bugzilla·2012-06-15·CVSS 4.0
[MEDIUM] mysql: Oracle CPU April 2012
mysql: Oracle CPU April 2012
This bug is for Oracle Critical Patch Update Advisory - April 2012 that lists 6 MySQL flaws:
http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html
Fixes for these issues are included in versions 5.1.62 and 5.5.22.
Previous CPU for MySQL was released in January 2012:
http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html
Security flaws in Jan 2012 CPU were fixed in versions 5.0.95, 5.1.61, and 5.5.20 (MySQL version 5.0.x reached end of life in between Jan and Apr CPUs). Therefore, following versions were released in between the two CPUs:
http://dev.mysql.com/doc/refman/5.1/en/news-5-1-62.html
http://dev.mysql.com/doc/refman/5.5/en/news-5-5-21.html
http://dev.mysql.com/doc/refman/5.5/en/news-5-5-22.html
The aim here is
Bugzilla
CVE-2012-2102 mysql: Server crash on HANDLER READ NEXT after DELETE
bugzilla·2012-04-13·CVSS 3.5
CVE-2012-2102 [LOW] CVE-2012-2102 mysql: Server crash on HANDLER READ NEXT after DELETE
CVE-2012-2102 mysql: Server crash on HANDLER READ NEXT after DELETE
A denial of service flaw was found in the way MySQL processed HANDLER READ NEXT statements after deleting a record. A remote, authenticated MySQL user could use this flaw to cause mysqld daemon abort (assertion failure).
References:
http://dev.mysql.com/doc/refman/5.5/en/news-5-5-22.html
http://dev.mysql.com/doc/refman/5.1/en/news-5-1-62.html
https://bugs.gentoo.org/show_bug.cgi?id=411503
http://eromang.zataz.com/2012/04/10/oracle-mysql-innodb-bugs-13510739-and-63775-dos-demo/
http://www.openwall.com/lists/oss-security/2012/04/13/7
Upstream commit:
http://bazaar.launchpad.net/~mysql/mysql-server/5.1/revision/3560.8.4
http://bazaar.launchpad.net/~mysql/mysql-server/5.5/revision/3097.15.15
Discussion:
Created mysql trac
http://bazaar.launchpad.net/~mysql/mysql-server/5.5/revision/3097.15.15http://dev.mysql.com/doc/refman/5.1/en/news-5-1-62.htmlhttp://dev.mysql.com/doc/refman/5.5/en/news-5-5-22.htmlhttp://eromang.zataz.com/2012/04/10/oracle-mysql-innodb-bugs-13510739-and-63775-dos-demo/http://secunia.com/advisories/53372http://security.gentoo.org/glsa/glsa-201308-06.xmlhttp://www.openwall.com/lists/oss-security/2012/04/13/7http://www.securityfocus.com/bid/52931http://bazaar.launchpad.net/~mysql/mysql-server/5.5/revision/3097.15.15http://dev.mysql.com/doc/refman/5.1/en/news-5-1-62.htmlhttp://dev.mysql.com/doc/refman/5.5/en/news-5-5-22.htmlhttp://eromang.zataz.com/2012/04/10/oracle-mysql-innodb-bugs-13510739-and-63775-dos-demo/http://secunia.com/advisories/53372http://security.gentoo.org/glsa/glsa-201308-06.xmlhttp://www.openwall.com/lists/oss-security/2012/04/13/7http://www.securityfocus.com/bid/52931
2012-08-17
Published