Input validation error in MySQL Server - CVE-2012-3163
Published: October 17, 2012 / Updated: August 4, 2020
MySQL Server
Detailed vulnerability description
The vulnerability allows a remote #AU# to execute arbitrary code.
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Information Schema. Per: http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html "The CVSS Base Score is 9.0 only for Windows. For Linux, Unix and other platforms, the CVSS Base Score is 6.5, and the impacts for Confidentiality, Integrity and Availability are Partial+."
How to mitigate CVE-2012-3163
Sources
- http://rhn.redhat.com/errata/RHSA-2012-1462.html
- http://secunia.com/advisories/51177
- http://secunia.com/advisories/51309
- http://secunia.com/advisories/53372
- http://secunia.com/advisories/56509
- http://secunia.com/advisories/56513
- http://security.gentoo.org/glsa/glsa-201308-06.xml
- http://support.f5.com/kb/en-us/solutions/public/14000/900/sol14907.html
- http://www.debian.org/security/2012/dsa-2581
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:150
- http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html
- http://www.ubuntu.com/usn/USN-1621-1
- https://exchange.xforce.ibmcloud.com/vulnerabilities/79381