CVE-2013-1861
published 2013-03-28CVE-2013-1861: MariaDB 5.5.x before 5.5.30, 5.3.x before 5.3.13, 5.2.x before 5.2.15, and 5.1.x before 5.1.68, and Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and…
PriorityP338medium5CVSS 2.0
AVNACLAuNCNINAP
EXPLOIT
EPSS
18.68%
96.9th percentile
MariaDB 5.5.x before 5.5.30, 5.3.x before 5.3.13, 5.2.x before 5.2.15, and 5.1.x before 5.1.68, and Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote attackers to cause a denial of service (crash) via a crafted geometry feature that specifies a large number of points, which is not properly handled when processing the binary representation of this feature, related to a numeric calculation error.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| mariadb | mariadb | >= 10.0.0 < 10.0.4 | 10.0.4 |
| mariadb | mariadb | >= 5.5.0 < 5.5.32 | 5.5.32 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| oracle | mysql | 5.1.0 – 5.1.69 | — |
| oracle | mysql | 5.5.0 – 5.5.31 | — |
| oracle | mysql | 5.6.0 – 5.6.11 | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_software_development_kit | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat5.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
MySQL vulnerabilities
vendor_ubuntu·2013-07-25
CVE-2013-1861 MySQL vulnerabilities
Title: MySQL vulnerabilities
Summary: Several security issues were fixed in MySQL.
Multiple security issues were discovered in MySQL and this update includes
new upstream MySQL versions to fix these issues.
MySQL has been updated to 5.1.70 in Ubuntu 10.04 LTS. Ubuntu 12.04 LTS,
Ubuntu 12.10 and Ubuntu 13.04 have been updated to MySQL 5.5.32.
In addition to security fixes, the updated packages contain bug fixes,
new features, and possibly incompatible changes.
Please see the following for more information:
http://dev.mysql.com/doc/relnotes/mysql/5.1/en/news-5-1-70.html
http://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-32.html
http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html
Instructions: In general, a standard system update will make all the necessary c
Red Hat
mysql: geometry query crashes mysqld (CPU July 2013)
vendor_redhat·2013-03-05·CVSS 5.0
CVE-2013-1861 [MEDIUM] mysql: geometry query crashes mysqld (CPU July 2013)
mysql: geometry query crashes mysqld (CPU July 2013)
MariaDB 5.5.x before 5.5.30, 5.3.x before 5.3.13, 5.2.x before 5.2.15, and 5.1.x before 5.1.68, and Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote attackers to cause a denial of service (crash) via a crafted geometry feature that specifies a large number of points, which is not properly handled when processing the binary representation of this feature, related to a numeric calculation error.
Statement: This issue was addressed in the package mysql55-mysql as shipped with Red Hat Enterprise Linux 5 via RHEA-2013:1330. This issue was addressed in the package mysql as shipped with Red Hat Enterprise Linux 6 via RHBA-2013:1647.
Package: mysql (Red Hat Enterprise Linux 5) - Under investigation
Pa
GHSA
GHSA-5cv5-75c5-879q: MariaDB 5
ghsa_unreviewed·2022-05-14
CVE-2013-1861 [MEDIUM] CWE-119 GHSA-5cv5-75c5-879q: MariaDB 5
MariaDB 5.5.x before 5.5.30, 5.3.x before 5.3.13, 5.2.x before 5.2.15, and 5.1.x before 5.1.68, and Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote attackers to cause a denial of service (crash) via a crafted geometry feature that specifies a large number of points, which is not properly handled when processing the binary representation of this feature, related to a numeric calculation error.
No detection rules found.
Bugzilla
CVE-2013-1861 mysql: geometry query crashes mysqld [fedora-all]
bugzilla·2013-03-15·CVSS 5.0
CVE-2013-1861 [MEDIUM] CVE-2013-1861 mysql: geometry query crashes mysqld [fedora-all]
CVE-2013-1861 mysql: geometry query crashes mysqld [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects multiple
Bugzilla
CVE-2013-1861 mysql: geometry query crashes mysqld (CPU July 2013)
bugzilla·2013-03-07·CVSS 5.0
CVE-2013-1861 [MEDIUM] CVE-2013-1861 mysql: geometry query crashes mysqld (CPU July 2013)
CVE-2013-1861 mysql: geometry query crashes mysqld (CPU July 2013)
Alyssa Milburn reported that when MySQL attempts to convert a binary string representation of a raw geometry object to a textual representation, the length checks in MySQL's spatial functions would overflow, resulting in a crash of mysqld (for instance, a query like "select astext(0x0100000000030000000100000000000010);" will cause the crash).
This has been reported to both upstream MariaDB [1] and Oracle [2]. A proposed patch is available [3].
[1] https://mariadb.atlassian.net/browse/MDEV-4252
[2] http://bugs.mysql.com/bug.php?id=68591
[3] http://lists.askmonty.org/pipermail/commits/2013-March/004371.html
Acknowledgements:
Red Hat would like to thank Alyssa Milburn for reporting this issue.
Discussion:
No CVE has be
http://lists.askmonty.org/pipermail/commits/2013-March/004371.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-08/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-10/msg00001.htmlhttp://lists.opensuse.org/opensuse-updates/2013-08/msg00024.htmlhttp://lists.opensuse.org/opensuse-updates/2013-09/msg00008.htmlhttp://seclists.org/oss-sec/2013/q1/671http://secunia.com/advisories/52639http://secunia.com/advisories/54300http://security.gentoo.org/glsa/glsa-201409-04.xmlhttp://www.debian.org/security/2013/dsa-2818http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.htmlhttp://www.osvdb.org/91415http://www.securityfocus.com/bid/58511http://www.ubuntu.com/usn/USN-1909-1https://bugzilla.redhat.com/show_bug.cgi?id=919247https://exchange.xforce.ibmcloud.com/vulnerabilities/82895https://mariadb.atlassian.net/browse/MDEV-4252http://lists.askmonty.org/pipermail/commits/2013-March/004371.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-08/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-10/msg00001.htmlhttp://lists.opensuse.org/opensuse-updates/2013-08/msg00024.htmlhttp://lists.opensuse.org/opensuse-updates/2013-09/msg00008.htmlhttp://seclists.org/oss-sec/2013/q1/671http://secunia.com/advisories/52639http://secunia.com/advisories/54300http://security.gentoo.org/glsa/glsa-201409-04.xmlhttp://www.debian.org/security/2013/dsa-2818http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.htmlhttp://www.osvdb.org/91415http://www.securityfocus.com/bid/58511http://www.ubuntu.com/usn/USN-1909-1https://bugzilla.redhat.com/show_bug.cgi?id=919247https://exchange.xforce.ibmcloud.com/vulnerabilities/82895https://mariadb.atlassian.net/browse/MDEV-4252
2013-03-28
Published