Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2012-5615

Опубликовано: 03 дек. 2012
Источник: debian
EPSS Средний

Описание

Oracle MySQL 5.5.38 and earlier, 5.6.19 and earlier, and MariaDB 5.5.28a, 5.3.11, 5.2.13, 5.1.66, and possibly other versions, generates different error messages with different time delays depending on whether a user name exists, which allows remote attackers to enumerate valid usernames.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mariadb-5.5not-affectedpackage
mysql-5.1removedpackage
mysql-5.1no-dsasqueezepackage
mysql-5.5fixed5.5.39-1package

Примечания

  • http://bazaar.launchpad.net/~mysql/mysql-server/5.5/revision/4676

  • https://mariadb.atlassian.net/browse/MDEV-3909

  • http://seclists.org/fulldisclosure/2012/Dec/9

EPSS

Процентиль: 95%
0.18495
Средний

Связанные уязвимости

ubuntu
почти 13 лет назад

Oracle MySQL 5.5.38 and earlier, 5.6.19 and earlier, and MariaDB 5.5.28a, 5.3.11, 5.2.13, 5.1.66, and possibly other versions, generates different error messages with different time delays depending on whether a user name exists, which allows remote attackers to enumerate valid usernames.

redhat
почти 13 лет назад

Oracle MySQL 5.5.38 and earlier, 5.6.19 and earlier, and MariaDB 5.5.28a, 5.3.11, 5.2.13, 5.1.66, and possibly other versions, generates different error messages with different time delays depending on whether a user name exists, which allows remote attackers to enumerate valid usernames.

nvd
почти 13 лет назад

Oracle MySQL 5.5.38 and earlier, 5.6.19 and earlier, and MariaDB 5.5.28a, 5.3.11, 5.2.13, 5.1.66, and possibly other versions, generates different error messages with different time delays depending on whether a user name exists, which allows remote attackers to enumerate valid usernames.

github
больше 3 лет назад

Oracle MySQL 5.5.38 and earlier, 5.6.19 and earlier, and MariaDB 5.5.28a, 5.3.11, 5.2.13, 5.1.66, and possibly other versions, generates different error messages with different time delays depending on whether a user name exists, which allows remote attackers to enumerate valid usernames.

suse-cvrf
почти 13 лет назад

Security update for MySQL

EPSS

Процентиль: 95%
0.18495
Средний