Input validation error in MySQL Server - CVE-2012-3163

 

Input validation error in MySQL Server - CVE-2012-3163

Published: October 17, 2012 / Updated: August 4, 2020


Vulnerability identifier: #VU33923
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-3163
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote #AU# to execute arbitrary code.

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Information Schema. Per: http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html "The CVSS Base Score is 9.0 only for Windows. For Linux, Unix and other platforms, the CVSS Base Score is 6.5, and the impacts for Confidentiality, Integrity and Availability are Partial+."


Affected software

MySQL Server
mysql (Alpine package)

How to mitigate CVE-2012-3163

Install update from vendor's website.

MySQL Server - addressed in versions 5.1.65, 5.5.26
mysql (Alpine package) - update to 5.5.28-r0

External References

Related Security Bulletins