Vulnerability Name:

CVE-2012-5612 (CCN-80440)

Assigned:2012-12-02
Published:2012-12-02
Updated:2022-07-20
Summary:Heap-based buffer overflow in Oracle MySQL 5.5.19 and other versions through 5.5.28, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code, as demonstrated using certain variations of the (1) USE, (2) SHOW TABLES, (3) DESCRIBE, (4) SHOW FIELDS FROM, (5) SHOW COLUMNS FROM, (6) SHOW INDEX FROM, (7) CREATE TABLE, (8) DROP TABLE, (9) ALTER TABLE, (10) DELETE FROM, (11) UPDATE, and (12) SET PASSWORD commands.
CVSS v3 Severity:5.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:6.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P)
5.1 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
6.5 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P)
5.1 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-787
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2012-5612

Source: CCN
Type: MySQL Web site
MySQL

Source: SUSE
Type: Mailing List, Third Party Advisory
SUSE-SU-2013:0262

Source: CCN
Type: Packetstorm Security Website
Oracle MySQL Heap Overrun

Source: FULLDISC
Type: Exploit, Mailing List, Third Party Advisory
20121201 MySQL (Linux) Heap Based Overrun PoC Zeroday

Source: CCN
Type: SA51427
Oracle MySQL Server Multiple Vulnerabilities

Source: SECUNIA
Type: Not Applicable
53372

Source: GENTOO
Type: Third Party Advisory
GLSA-201308-06

Source: EXPLOIT-DB
Type: Exploit, Third Party Advisory, VDB Entry
23076

Source: MANDRIVA
Type: Broken Link
MDVSA-2013:102

Source: MANDRIVA
Type: Broken Link
MDVSA-2013:150

Source: MLIST
Type: Mailing List, Third Party Advisory
[oss-security] 20121202 Re: Re: [Full-disclosure] MySQL (Linux) Stack based buffer overrun PoC Zeroday

Source: MLIST
Type: Mailing List, Third Party Advisory
[oss-security] 20121202 Re: Re: [Full-disclosure] MySQL (Linux) Stack based buffer overrun PoC Zeroday

Source: CCN
Type: Oracle Web site
Oracle Critical Patch Update Advisory - January 2013

Source: CONFIRM
Type: Vendor Advisory
http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html

Source: CCN
Type: OSVDB ID: 88064
Oracle MySQL Server Multiple-Table DELETE Heap Buffer Overflow

Source: CCN
Type: BID-56768
Oracle MySQL Server Heap Overflow Vulnerability

Source: UBUNTU
Type: Third Party Advisory
USN-1703-1

Source: XF
Type: UNKNOWN
mysql-server-table-bo(80440)

Source: CONFIRM
Type: Broken Link, Exploit, Patch
https://mariadb.atlassian.net/browse/MDEV-3908

Source: OVAL
Type: Third Party Advisory
oval:org.mitre.oval:def:16960

Source: EXPLOIT-DB
Type: EXPLOIT
Offensive Security Exploit Database [12-02-2012]

Vulnerable Configuration:Configuration 1:
  • cpe:/a:mariadb:mariadb:10.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:mariadb:mariadb:*:*:*:*:*:*:*:* (Version >= 5.2.0 and < 5.2.14)
  • OR cpe:/a:mariadb:mariadb:*:*:*:*:*:*:*:* (Version >= 5.3.0 and < 5.3.12)
  • OR cpe:/a:mariadb:mariadb:*:*:*:*:*:*:*:* (Version >= 5.5.0 and < 5.5.29)
  • OR cpe:/a:mariadb:mariadb:*:*:*:*:*:*:*:* (Version >= 5.1.0 and < 5.1.67)

  • Configuration 2:
  • cpe:/a:oracle:mysql:*:*:*:*:*:*:*:* (Version >= 5.5.0 and <= 5.5.28)

  • Configuration 3:
  • cpe:/o:suse:linux_enterprise_desktop:11:sp2:*:*:*:*:*:*
  • OR cpe:/o:suse:linux_enterprise_server:11:sp2:*:*:*:vmware:*:*
  • OR cpe:/o:suse:linux_enterprise_software_development_kit:11:sp2:*:*:*:*:*:*
  • OR cpe:/o:suse:linux_enterprise_server:11:sp2:*:*:*:-:*:*

  • Configuration 4:
  • cpe:/o:canonical:ubuntu_linux:11.10:*:*:*:*:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*

  • Configuration CCN 1:
  • cpe:/a:oracle:mysql:5.1.53:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:mysql:5.5.19:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20125612
    V
    CVE-2012-5612
    2022-06-30
    oval:org.opensuse.security:def:993
    P
    Security update for helm-mirror (Moderate)
    2022-05-31
    oval:org.opensuse.security:def:1515
    P
    Security update for MozillaThunderbird (Important)
    2022-05-17
    oval:org.opensuse.security:def:112715
    P
    libmysqlclient-devel-10.0.22-3.8 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:33109
    P
    Security update for java-1_8_0-ibm (Important) (in QA)
    2022-01-04
    oval:org.opensuse.security:def:26187
    P
    Security update for libvpx (Moderate)
    2021-12-23
    oval:org.opensuse.security:def:26186
    P
    Security update for libqt4 (Important)
    2021-12-22
    oval:org.opensuse.security:def:34611
    P
    Security update for bcm43xx-firmware (Important)
    2021-12-13
    oval:org.opensuse.security:def:64636
    P
    Security update for python3 (Moderate)
    2021-12-13
    oval:org.opensuse.security:def:1048
    P
    Security update for wireshark (Moderate)
    2021-12-06
    oval:org.opensuse.security:def:29442
    P
    Security update for binutils (Moderate)
    2021-11-09
    oval:org.opensuse.security:def:34571
    P
    Security update for git (Low)
    2021-10-20
    oval:org.opensuse.security:def:68070
    P
    Security update for the Linux Kernel (Live Patch 18 for SLE 15 SP1) (Important)
    2021-10-14
    oval:org.opensuse.security:def:106188
    P
    libmysqlclient-devel-10.0.22-3.8 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:33720
    P
    Security update for MozillaFirefox (Important)
    2021-09-22
    oval:org.opensuse.security:def:71423
    P
    xscreensaver-5.37-3.51 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:90050
    P
    libmysqld-devel-10.2.22-3.14.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:97015
    P
    libmysqld-devel-10.2.22-3.14.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:103705
    P
    libmysqld-devel-10.2.22-3.14.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:71310
    P
    libserf-1-1-1.3.9-2.31 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:63215
    P
    libmysqld-devel-10.2.22-3.14.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:2126
    P
    libmysqld-devel-10.2.22-3.14.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:48215
    P
    libvirglrenderer0-0.5.0-11.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48067
    P
    libQt5Concurrent5-5.6.2-6.15.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47975
    P
    coreutils-8.25-13.7.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47843
    P
    pam_ssh-2.0-1.39 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47650
    P
    java-1_7_0-openjdk-1.7.0.181-43.15.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47529
    P
    xdg-utils-20140630-5.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47515
    P
    tftp-5.2-10.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47514
    P
    tcpdump-4.9.0-13.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48270
    P
    perl-XML-LibXML-2.0019-6.3.5 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48122
    P
    libhivex0-1.3.10-4.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48030
    P
    grub2-2.02-12.15.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47898
    P
    syslog-service-2.0-778.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47705
    P
    libexif12-0.6.21-8.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47584
    P
    cups-1.7.5-20.17.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47570
    P
    bzip2-1.0.6-29.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47569
    P
    busybox-1.21.1-3.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:64723
    P
    Security update for libgcrypt (Important)
    2021-06-24
    oval:org.opensuse.security:def:1570
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:29385
    P
    Security update for webkit2gtk3 (Important)
    2021-06-17
    oval:org.opensuse.security:def:55209
    P
    Security update for apache2 (Important)
    2021-06-17
    oval:org.opensuse.security:def:33933
    P
    Security update for apache2 (Important)
    2021-06-17
    oval:org.opensuse.security:def:48742
    P
    libqt4-sql-mysql-32bit-4.8.6-4.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48671
    P
    freerdp-1.0.2-7.9 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48640
    P
    update-alternatives-1.18.4-14.216 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48575
    P
    logwatch-7.4.3-15.65 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48513
    P
    libjson-c2-0.11-2.15 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48429
    P
    glibc-2.22-49.16 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48797
    P
    libpolkit0-32bit-0.113-5.6.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48726
    P
    icu-52.1-7.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48695
    P
    libssh4-0.6.3-1.4 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48630
    P
    sysconfig-0.84.0-13.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48568
    P
    libvte9-0.28.2-19.7 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48484
    P
    libblkid1-2.28-40.28 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:67970
    P
    Security update for the Linux Kernel (Live Patch 19 for SLE 15 SP1) (Important)
    2021-04-28
    oval:org.opensuse.security:def:55887
    P
    Security update for qemu (Important)
    2021-04-22
    oval:org.opensuse.security:def:33889
    P
    Security update for spamassassin (Important)
    2021-04-12
    oval:org.opensuse.security:def:33098
    P
    Security update for python3 (Moderate)
    2021-03-19
    oval:org.opensuse.security:def:33097
    P
    Security update for glib2 (Important)
    2021-03-16
    oval:org.opensuse.security:def:33777
    P
    Security update for openldap2 (Important)
    2021-03-03
    oval:org.opensuse.security:def:26198
    P
    Security update for avahi (Moderate)
    2021-02-23
    oval:org.opensuse.security:def:54764
    P
    Security update for java-1_8_0-openjdk (Moderate)
    2021-02-19
    oval:org.opensuse.security:def:57163
    P
    Security update for wpa_supplicant (Important)
    2021-02-15
    oval:org.opensuse.security:def:29299
    P
    Security update for gdm (Important)
    2020-12-03
    oval:org.opensuse.security:def:63160
    P
    libmysqld-devel-10.2.15-1.3 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2071
    P
    libmysqld-devel-10.2.15-1.3 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:55768
    P
    Security update for python-setuptools (Important)
    2020-12-02
    oval:org.opensuse.security:def:33475
    P
    Security update for Mozilla
    2020-12-01
    oval:org.opensuse.security:def:27843
    P
    Security update for net-snmp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33418
    P
    Security update for NetworkManager
    2020-12-01
    oval:org.opensuse.security:def:27804
    P
    Security update for libpng
    2020-12-01
    oval:org.opensuse.security:def:29087
    P
    Security update for MozillaFirefox, mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:33323
    P
    Security update for curl (Important)
    2020-12-01
    oval:org.opensuse.security:def:27755
    P
    Security update for glibc
    2020-12-01
    oval:org.opensuse.security:def:33188
    P
    libtspi1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27702
    P
    Security update for a2ps
    2020-12-01
    oval:org.opensuse.security:def:27551
    P
    quagga on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:57237
    P
    Security update for MySQL
    2020-12-01
    oval:org.opensuse.security:def:27467
    P
    libnewt0_52 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49957
    P
    libopenvswitch-2_8-0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27410
    P
    git on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28539
    P
    Security update for CUPS
    2020-12-01
    oval:org.opensuse.security:def:27328
    P
    xorg-x11-Xvnc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29884
    P
    Security update for libX11 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27200
    P
    libneon27 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29840
    P
    Security update for Linux kernel
    2020-12-01
    oval:org.opensuse.security:def:27136
    P
    gnome-screensaver on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29822
    P
    Security update for java-1_6_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:27635
    P
    Security update for MySQL
    2020-12-01
    oval:org.opensuse.security:def:27125
    P
    foomatic-filters on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29783
    P
    Security update for gpg2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29734
    P
    Security update for foomatic-filters (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29680
    P
    Security update for ecryptfs-utils
    2020-12-01
    oval:org.opensuse.security:def:29527
    P
    Security update for MozillaFirefox (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30522
    P
    Security update for hplip
    2020-12-01
    oval:org.opensuse.security:def:29168
    P
    Security update for mailman (Important)
    2020-12-01
    oval:org.opensuse.security:def:55806
    P
    Security update for flex, at, bogofilter, cyrus-imapd, kdelibs4, libQtWebKit4, libbonobo, mdbtools, netpbm, openslp, sgmltool, virtuoso, libqt5-qtwebkit (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29099
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.opensuse.security:def:28574
    P
    Security update for MySQL
    2020-12-01
    oval:org.opensuse.security:def:29088
    P
    Security update for gcc43 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55694
    P
    Security update for ghostscript (Low)
    2020-12-01
    oval:org.opensuse.security:def:55602
    P
    Security update for xdg-utils (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55494
    P
    Security update for libXfont (Important)
    2020-12-01
    oval:org.opensuse.security:def:26962
    P
    libotr2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26918
    P
    ibutils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49956
    P
    libmysqld-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55043
    P
    xorg-x11-libs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26904
    P
    glib2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54937
    P
    libtasn1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26865
    P
    apache2-mod_php53 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27124
    P
    findutils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26816
    P
    radvd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54526
    P
    libXt6 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26763
    P
    libqt4-sql-mysql on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54386
    P
    syslog-service on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26612
    P
    man on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33865
    P
    Security update for jasper (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30559
    P
    Security update for MySQL
    2020-12-01
    oval:org.opensuse.security:def:54364
    P
    python-cupshelpers on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26528
    P
    bzip2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33826
    P
    Security update for glibc
    2020-12-01
    oval:org.opensuse.security:def:49902
    P
    rmt-server-pubcloud on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54363
    P
    python on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26471
    P
    Security update for Mozilla Thunderbird (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27600
    P
    Security update for apache2-mod_security2
    2020-12-01
    oval:org.opensuse.security:def:26390
    P
    Security update for ark (Low)
    2020-12-01
    oval:org.opensuse.security:def:27901
    P
    Security update for xalan-j2
    2020-12-01
    oval:org.opensuse.security:def:26262
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:33563
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27857
    P
    Security update for postgresql91
    2020-12-01
    oval:org.opensuse.security:def:50011
    P
    libmysqld-devel on GA media (Moderate)
    2020-12-01
    oval:org.mitre.oval:def:16960
    V
    Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server Parser). Supported versions that are affected are 5.5.28 and earlier. Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution
    2015-06-01
    oval:org.mitre.oval:def:25951
    P
    SUSE-SU-2013:0262-1 -- Security update for MySQL
    2014-09-08
    oval:org.mitre.oval:def:18161
    P
    USN-1703-1 -- mysql-5.1, mysql-5.5, mysql-dfsg-5.1 vulnerabilities
    2014-06-30
    oval:org.opensuse.security:def:79871
    P
    Security update for MySQL
    2012-12-27
    oval:com.ubuntu.precise:def:20125612000
    V
    CVE-2012-5612 on Ubuntu 12.04 LTS (precise) - medium.
    2012-12-03
    BACK
    mariadb mariadb 10.0.0
    mariadb mariadb *
    mariadb mariadb *
    mariadb mariadb *
    mariadb mariadb *
    oracle mysql *
    suse linux enterprise desktop 11 sp2
    suse linux enterprise server 11 sp2
    suse linux enterprise software development kit 11 sp2
    suse linux enterprise server 11 sp2
    canonical ubuntu linux 11.10
    canonical ubuntu linux 12.10
    canonical ubuntu linux 10.04
    canonical ubuntu linux 12.04
    oracle mysql 5.1.53
    oracle mysql 5.5.19