Improper Authentication in MySQL Server - CVE-2012-2122

 

Improper Authentication in MySQL Server - CVE-2012-2122

Published: June 26, 2012 / Updated: July 29, 2020


Vulnerability identifier: #VU32786
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-2122
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x before 5.1.62, 5.2.x before 5.2.12, 5.3.x before 5.3.6, and 5.5.x before 5.5.23, when running in certain environments with certain implementations of the memcmp function, allows remote attackers to bypass authentication by repeatedly authenticating with the same incorrect password, which eventually causes a token comparison to succeed due to an improperly-checked return value.


Affected software

MySQL Server
Amazon Linux AMI
SUSE Linux
mysql (Alpine package)

How to mitigate CVE-2012-2122

Install update from vendor's website.

MySQL Server - addressed in versions 5.1.62, 5.1.63, 5.5.23, 5.5.24, 5.6.6
mysql (Alpine package) - update to 5.1.63-r0

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins