CVE-2012-2122
sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x before 5.1.62, 5.2.x before 5.2.12, 5.3.x before 5.3.6, and 5.5.x before 5.5.23, when running in certain environments with certain…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 96.5%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x before 5.1.62, 5.2.x before 5.2.12, 5.3.x before 5.3.6, and 5.5.x before 5.5.23, when running in certain environments with certain implementations of the memcmp function, allows remote attackers to bypass authentication by repeatedly authenticating with the same incorrect password, which eventually causes a token comparison to succeed due to an improperly-checked return value.
- CVSS 2.0
- 5.1 MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
- EPSS
- 96.50% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- oracle/mysql · mariadb/mariadb
- Source
- secalert@redhat.com
References
- http://bugs.mysql.com/bug.php?id=64884Exploit
- http://kb.askmonty.org/en/mariadb-5162-release-notes/
- http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00007.html
- http://seclists.org/oss-sec/2012/q2/493Patch
- http://secunia.com/advisories/49417Vendor Advisory
- http://secunia.com/advisories/53372
- http://security.gentoo.org/glsa/glsa-201308-06.xml
- http://securitytracker.com/id?1027143
- http://www.exploit-db.com/exploits/19092
- http://www.securityfocus.com/bid/53911Exploit
- https://community.rapid7.com/community/metasploit/blog/2012/06/11/cve-2012-2122-a-tragically-comedic-security-flaw-in-mysqlExploit
- http://bugs.mysql.com/bug.php?id=64884Exploit
- http://kb.askmonty.org/en/mariadb-5162-release-notes/
- http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00007.html
- http://seclists.org/oss-sec/2012/q2/493Patch
- http://secunia.com/advisories/49417Vendor Advisory
- http://secunia.com/advisories/53372
- http://security.gentoo.org/glsa/glsa-201308-06.xml
- http://securitytracker.com/id?1027143
- http://www.exploit-db.com/exploits/19092
- http://www.securityfocus.com/bid/53911Exploit
- https://community.rapid7.com/community/metasploit/blog/2012/06/11/cve-2012-2122-a-tragically-comedic-security-flaw-in-mysqlExploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.