CVE-2012-2749
published 2012-08-17CVE-2012-2749: MySQL 5.1.x before 5.1.63 and 5.5.x before 5.5.24 allows remote authenticated users to cause a denial of service (mysqld crash) via vectors related to…
PriorityP414medium4CVSS 2.0
AVNACLAuSCNINAP
EPSS
1.90%
77.3th percentile
MySQL 5.1.x before 5.1.63 and 5.5.x before 5.5.24 allows remote authenticated users to cause a denial of service (mysqld crash) via vectors related to incorrect calculation and a sort order index.
Affected
90 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| mysql | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
| oracle | mysql | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
mysql: crash caused by wrong calculation of key length for sort order index
vendor_redhat·2012-04-04·CVSS 4.0
CVE-2012-2749 [MEDIUM] mysql: crash caused by wrong calculation of key length for sort order index
mysql: crash caused by wrong calculation of key length for sort order index
MySQL 5.1.x before 5.1.63 and 5.5.x before 5.5.24 allows remote authenticated users to cause a denial of service (mysqld crash) via vectors related to incorrect calculation and a sort order index.
GHSA
GHSA-3rhr-hm6q-fchf: MySQL 5
ghsa_unreviewed·2022-05-13
CVE-2012-2749 [MEDIUM] GHSA-3rhr-hm6q-fchf: MySQL 5
MySQL 5.1.x before 5.1.63 and 5.5.x before 5.5.24 allows remote authenticated users to cause a denial of service (mysqld crash) via vectors related to incorrect calculation and a sort order index.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-1734 mysql: unspecified DoS vulnerability related to Server Optimizer (CPU Jul 2012)
bugzilla·2012-07-18·CVSS 4.0
CVE-2012-1734 [MEDIUM] CVE-2012-1734 mysql: unspecified DoS vulnerability related to Server Optimizer (CPU Jul 2012)
CVE-2012-1734 mysql: unspecified DoS vulnerability related to Server Optimizer (CPU Jul 2012)
Common Vulnerabilities and Exposures assigned an identifier CVE-2012-1734 to
the following vulnerability:
Name: CVE-2012-1734
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1734
Assigned: 20120316
Reference: http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.html
Unspecified vulnerability in Oracle MySQL Server 5.1.62 and earlier,
and 5.5.23 and earlier, allows remote authenticated users to affect
availability via unknown vectors related to Server Optimizer.
Discussion:
Reviewing changes between 5.1.62 and 5.1.63, there are several fixes that are likely all hidden under this single CVE. All these were also fixed in 5.5 in between 5.5.23 and 5.5.24.
---
http://b
Bugzilla
CVE-2012-2749 mysql: crash caused by wrong calculation of key length for sort order index
bugzilla·2012-06-20·CVSS 4.0
CVE-2012-2749 [MEDIUM] CVE-2012-2749 mysql: crash caused by wrong calculation of key length for sort order index
CVE-2012-2749 mysql: crash caused by wrong calculation of key length for sort order index
MySQL versions 5.1.63 and 5.5.24 fix the following bug noted in the 5.1.63 release notes:
* Security Fix: Bug #59387 was fixed.
http://dev.mysql.com/doc/refman/5.1/en/news-5-1-63.html
This bug is also fixed in 5.5.24, but not mentioned in the release notes or changelog.
Related upstream change is:
http://bazaar.launchpad.net/~mysql/mysql-server/5.1/revision/3560.10.16
Bug#11766300 59387: FAILING ASSERTION: CURSOR->POS_STATE == 1997660512 (BTR_PCUR_IS_POSITIONE
Bug#13639204 64111: CRASH ON SELECT SUBQUERY WITH NON UNIQUE INDEX
This issue allows non-admin database user with full SQL access to crash mysqld. Upstream commit explains issue details:
The crash happened due to wrong calculation of key
http://dev.mysql.com/doc/refman/5.1/en/news-5-1-63.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1462.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0180.htmlhttp://secunia.com/advisories/51309http://secunia.com/advisories/53372http://security.gentoo.org/glsa/glsa-201308-06.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2013:150http://www.securityfocus.com/bid/55120https://bugzilla.redhat.com/show_bug.cgi?id=833737http://dev.mysql.com/doc/refman/5.1/en/news-5-1-63.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1462.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0180.htmlhttp://secunia.com/advisories/51309http://secunia.com/advisories/53372http://security.gentoo.org/glsa/glsa-201308-06.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2013:150http://www.securityfocus.com/bid/55120https://bugzilla.redhat.com/show_bug.cgi?id=833737
2012-08-17
Published