CVE-2012-5627
01.10.2013, 17:55
Oracle MySQL and MariaDB 5.5.x before 5.5.29, 5.3.x before 5.3.12, and 5.2.x before 5.2.14 does not modify the salt during multiple executions of the change_user command within the same connection which makes it easier for remote authenticated users to conduct brute force password guessing attacks.Enginsight
Vendor | Product | Version |
---|---|---|
oracle | mysql | 5.5.0 ≤ 𝑥 < 5.5.29 |
mariadb | mariadb | 5.2.0 ≤ 𝑥 < 5.2.14 |
mariadb | mariadb | 5.3.0 ≤ 𝑥 < 5.3.12 |
mariadb | mariadb | 5.5.0 ≤ 𝑥 < 5.5.29 |
mariadb | mariadb | 10.0.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
mariadb-5.5 |
| ||||||||||||||||||||||||||
mysql-5.5 |
| ||||||||||||||||||||||||||
mysql-5.6 |
|
Common Weakness Enumeration
References