SB2012011903 - Multiple vulnerabilities in Google, mysql
Published: January 19, 2012 Updated: August 11, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 8 secuirty vulnerabilities.
1) Buffer overflow (CVE-ID: CVE-2012-0882)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
Buffer overflow in yaSSL, as used in MySQL 5.5.20 and possibly other versions including 5.5.x before 5.5.22 and 5.1.x before 5.1.62, allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by VulnDisco Pack Professional 9.17. NOTE: as of 20120224, this disclosure has no actionable information. However, because the module author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes. NOTE: due to lack of details, it is not clear whether this issue is a duplicate of CVE-2012-0492 or another CVE.
2) Buffer overflow (CVE-ID: CVE-2012-2102)
The vulnerability allows a remote #AU# to perform service disruption.
MySQL 5.1.x before 5.1.62 and 5.5.x before 5.5.22 allows remote authenticated users to cause a denial of service (assertion failure and mysqld abort) by deleting a record and using HANDLER READ NEXT.
3) Input validation error (CVE-ID: CVE-2012-0484)
The vulnerability allows a remote #AU# to gain access to sensitive information.
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.0.x, 5.1.x, and 5.5.x allows remote authenticated users to affect confidentiality via unknown vectors.
4) Input validation error (CVE-ID: CVE-2012-0485)
The vulnerability allows a remote #AU# to perform service disruption.
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0112, CVE-2012-0115, CVE-2012-0119, CVE-2012-0120, and CVE-2012-0492.
5) Input validation error (CVE-ID: CVE-2012-0486)
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0117, CVE-2012-0487, CVE-2012-0488, CVE-2012-0489, CVE-2012-0491, CVE-2012-0493, and CVE-2012-0495.
6) Input validation error (CVE-ID: CVE-2012-0487)
The vulnerability allows a remote #AU# to perform service disruption.
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0117, CVE-2012-0486, CVE-2012-0488, CVE-2012-0489, CVE-2012-0491, CVE-2012-0493, and CVE-2012-0495.
7) Input validation error (CVE-ID: CVE-2012-0488)
The vulnerability allows a remote #AU# to perform service disruption.
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0117, CVE-2012-0486, CVE-2012-0487, CVE-2012-0489, CVE-2012-0491, CVE-2012-0493, and CVE-2012-0495.
8) Input validation error (CVE-ID: CVE-2012-0489)
The vulnerability allows a remote #AU# to perform service disruption.
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0117, CVE-2012-0486, CVE-2012-0487, CVE-2012-0488, CVE-2012-0491, CVE-2012-0493, and CVE-2012-0495.
Remediation
Install update from vendor's website.
References
- http://www.openwall.com/lists/oss-security/2012/02/24/2
- https://blogs.oracle.com/sunsecurity/entry/cve_2012_0882buffer_overflow_vulnerability
- https://bugzilla.redhat.com/show_bug.cgi?id=789141
- https://lists.immunityinc.com/pipermail/canvas/2012-February/000011.html
- https://lists.immunityinc.com/pipermail/canvas/2012-February/000014.html
- http://bazaar.launchpad.net/~mysql/mysql-server/5.5/revision/3097.15.15
- http://dev.mysql.com/doc/refman/5.1/en/news-5-1-62.html
- http://dev.mysql.com/doc/refman/5.5/en/news-5-5-22.html
- http://eromang.zataz.com/2012/04/10/oracle-mysql-innodb-bugs-13510739-and-63775-dos-demo/
- http://secunia.com/advisories/53372
- http://security.gentoo.org/glsa/glsa-201308-06.xml
- http://www.openwall.com/lists/oss-security/2012/04/13/7
- http://www.securityfocus.com/bid/52931
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=659687
- http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00007.html
- http://osvdb.org/78372
- http://secunia.com/advisories/48250
- http://www.debian.org/security/2012/dsa-2429
- http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html
- http://www.securityfocus.com/bid/51515
- http://www.ubuntu.com/usn/USN-1397-1
- https://exchange.xforce.ibmcloud.com/vulnerabilities/72525
- http://osvdb.org/78383
- http://www.securityfocus.com/bid/51513
- https://exchange.xforce.ibmcloud.com/vulnerabilities/72526
- http://osvdb.org/78384
- http://www.securityfocus.com/bid/51514
- https://exchange.xforce.ibmcloud.com/vulnerabilities/72527
- http://osvdb.org/78385
- http://www.securityfocus.com/bid/51503
- https://exchange.xforce.ibmcloud.com/vulnerabilities/72528
- http://osvdb.org/78386
- http://www.securityfocus.com/bid/51506
- https://exchange.xforce.ibmcloud.com/vulnerabilities/72529
- http://osvdb.org/78387
- http://www.securityfocus.com/bid/51510
- https://exchange.xforce.ibmcloud.com/vulnerabilities/72530