Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-5615

Опубликовано: 01 дек. 2012
Источник: redhat
CVSS2: 3.5
EPSS Средний

Описание

Oracle MySQL 5.5.38 and earlier, 5.6.19 and earlier, and MariaDB 5.5.28a, 5.3.11, 5.2.13, 5.1.66, and possibly other versions, generates different error messages with different time delays depending on whether a user name exists, which allows remote attackers to enumerate valid usernames.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6mysqlUnder investigation
Red Hat Enterprise Linux 5mysql55-mysqlFixedRHSA-2014:185917.11.2014
Red Hat Enterprise Linux 7mariadbFixedRHSA-2014:186117.11.2014
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6mariadb-galeraFixedRHSA-2014:193702.12.2014
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7mariadb-galeraFixedRHSA-2014:194002.12.2014
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6mysql55-mysqlFixedRHSA-2014:186017.11.2014
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6mariadb55-mariadbFixedRHSA-2014:186217.11.2014
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.4 EUSmysql55-mysqlFixedRHSA-2014:186017.11.2014
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.4 EUSmariadb55-mariadbFixedRHSA-2014:186217.11.2014
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.5 EUSmysql55-mysqlFixedRHSA-2014:186017.11.2014

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-209
https://bugzilla.redhat.com/show_bug.cgi?id=882608mysql: Remote Preauth User Enumeration flaw

EPSS

Процентиль: 95%
0.20664
Средний

3.5 Low

CVSS2

Связанные уязвимости

ubuntu
около 13 лет назад

Oracle MySQL 5.5.38 and earlier, 5.6.19 and earlier, and MariaDB 5.5.28a, 5.3.11, 5.2.13, 5.1.66, and possibly other versions, generates different error messages with different time delays depending on whether a user name exists, which allows remote attackers to enumerate valid usernames.

nvd
около 13 лет назад

Oracle MySQL 5.5.38 and earlier, 5.6.19 and earlier, and MariaDB 5.5.28a, 5.3.11, 5.2.13, 5.1.66, and possibly other versions, generates different error messages with different time delays depending on whether a user name exists, which allows remote attackers to enumerate valid usernames.

debian
около 13 лет назад

Oracle MySQL 5.5.38 and earlier, 5.6.19 and earlier, and MariaDB 5.5.2 ...

github
больше 3 лет назад

Oracle MySQL 5.5.38 and earlier, 5.6.19 and earlier, and MariaDB 5.5.28a, 5.3.11, 5.2.13, 5.1.66, and possibly other versions, generates different error messages with different time delays depending on whether a user name exists, which allows remote attackers to enumerate valid usernames.

suse-cvrf
около 13 лет назад

Security update for MySQL

EPSS

Процентиль: 95%
0.20664
Средний

3.5 Low

CVSS2