Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2012-5614

Опубликовано: 03 дек. 2012
Источник: debian

Описание

Oracle MySQL 5.1.67 and earlier and 5.5.29 and earlier, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a denial of service (mysqld crash) via a SELECT command with an UpdateXML command containing XML with a large number of unique, nested elements.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mariadb-5.5not-affectedpackage
mysql-5.5not-affectedpackage
mysql-5.1removedpackage
mysql-5.1fixed5.1.73-1squeezepackage

Примечания

  • https://mariadb.atlassian.net/browse/MDEV-3910

  • http://seclists.org/fulldisclosure/2012/Dec/7

  • https://www.openwall.com/lists/oss-security/2013/02/28/10

Связанные уязвимости

ubuntu
больше 12 лет назад

Oracle MySQL 5.1.67 and earlier and 5.5.29 and earlier, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a denial of service (mysqld crash) via a SELECT command with an UpdateXML command containing XML with a large number of unique, nested elements.

redhat
больше 12 лет назад

Oracle MySQL 5.1.67 and earlier and 5.5.29 and earlier, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a denial of service (mysqld crash) via a SELECT command with an UpdateXML command containing XML with a large number of unique, nested elements.

nvd
больше 12 лет назад

Oracle MySQL 5.1.67 and earlier and 5.5.29 and earlier, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a denial of service (mysqld crash) via a SELECT command with an UpdateXML command containing XML with a large number of unique, nested elements.

github
около 3 лет назад

Oracle MySQL 5.1.67 and earlier and 5.5.29 and earlier, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a denial of service (mysqld crash) via a SELECT command with an UpdateXML command containing XML with a large number of unique, nested elements.

oracle-oval
около 12 лет назад

ELSA-2013-0772: mysql security update (IMPORTANT)