CVE-2013-0386
published 2013-01-17CVE-2013-0386: Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users to affect availability via unknown…
PriorityP427medium6.8CVSS 2.0
AVNACLAuSCNINAC
EPSS
2.95%
85.6th percentile
Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users to affect availability via unknown vectors related to Stored Procedure.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| mariadb | mariadb | — | — |
| mariadb | mariadb | >= 5.5.0 < 5.5.29 | 5.5.29 |
| oracle | mysql | 5.5.0 – 5.5.28 | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:C
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f239-hj2h-5hv8: Unspecified vulnerability in the Server component in Oracle MySQL 5
ghsa_unreviewed·2022-05-05
CVE-2013-0386 [MEDIUM] GHSA-f239-hj2h-5hv8: Unspecified vulnerability in the Server component in Oracle MySQL 5
Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users to affect availability via unknown vectors related to Stored Procedure.
Ubuntu
MySQL vulnerabilities
vendor_ubuntu·2013-01-22
CVE-2012-0572 MySQL vulnerabilities
Title: MySQL vulnerabilities
Summary: Several security issues were fixed in MySQL.
Multiple security issues were discovered in MySQL and this update includes
new upstream MySQL versions to fix these issues.
MySQL has been updated to 5.1.67 in Ubuntu 10.04 LTS and Ubuntu 11.10.
Ubuntu 12.04 LTS and Ubuntu 12.10 have been updated to MySQL 5.5.29.
In addition to security fixes, the updated packages contain bug fixes, new
features, and possibly incompatible changes.
Please see the following for more information:
http://dev.mysql.com/doc/relnotes/mysql/5.1/en/news-5-1-67.html
http://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-29.html
http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html
Instructions: In general, a standard system update will make all the necessary
Red Hat
mysql: unspecified DoS vulnerability related to Stored Procedure (CPU Jan 2013)
vendor_redhat·2013-01-15·CVSS 6.8
CVE-2013-0386 [MEDIUM] mysql: unspecified DoS vulnerability related to Stored Procedure (CPU Jan 2013)
mysql: unspecified DoS vulnerability related to Stored Procedure (CPU Jan 2013)
Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users to affect availability via unknown vectors related to Stored Procedure.
Statement: Not vulnerable. Upstream notes this issue only affected MySQL 5.5.x. Red Hat Enterprise Linux 5 and 6 include MySQL versions 5.0.x and 5.1.x respectively, which are not listed as affected.
Package: mysql (Red Hat Enterprise Linux 5) - Not affected
Package: mysql (Red Hat Enterprise Linux 6) - Not affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-6136 tuned: insecure permissions of tuned.pid
bugzilla·2013-03-06·CVSS 5.5
CVE-2012-6136 [MEDIUM] CVE-2012-6136 tuned: insecure permissions of tuned.pid
CVE-2012-6136 tuned: insecure permissions of tuned.pid
Aaron Parsons reported [1] that tuned would create its PID file with insecure permissions (0666). A local user could use this flaw to kill arbitrary running processes when the tuned service is stopped.
This was fixed upstream [2] and was also previously corrected in Red Hat Enterprise Linux 6 via RHBA-2013:0386 [3].
Current Fedora 18 inherited the upstream fix, however Fedora 17 is still affected by this issue.
[1] https://bugzilla.redhat.com/show_bug.cgi?id=845336
[2] http://git.fedorahosted.org/cgit/tuned.git/commit/?h=1.0&id=9e8f670
[3] http://rhn.redhat.com/errata/RHBA-2013-0386.html
Discussion:
Created tuned tracking bugs for this issue
Affects: fedora-17 [bug 918233]
Bugzilla
CVE-2013-0386 mysql: unspecified DoS vulnerability related to Stored Procedure (CPU Jan 2013)
bugzilla·2013-01-16·CVSS 6.8
CVE-2013-0386 [MEDIUM] CVE-2013-0386 mysql: unspecified DoS vulnerability related to Stored Procedure (CPU Jan 2013)
CVE-2013-0386 mysql: unspecified DoS vulnerability related to Stored Procedure (CPU Jan 2013)
An unspecified vulnerability in the stored procedure subcomponent of the MySQL protocol component of the Oracle MySQL server allows remote authenticated attackers to alter availability via unspecified vectors.
References:
[1] http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html
Discussion:
Text of the Oracle flaw description:
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Stored Procedure). Supported versions that are affected are 5.5.28 and earlier. Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized Operating System hang or
http://secunia.com/advisories/53372http://security.gentoo.org/glsa/glsa-201308-06.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2013:150http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.htmlhttp://www.ubuntu.com/usn/USN-1703-1https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16835http://secunia.com/advisories/53372http://security.gentoo.org/glsa/glsa-201308-06.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2013:150http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.htmlhttp://www.ubuntu.com/usn/USN-1703-1https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16835
2013-01-17
Published