mysql: efficient password guessing attack using change_user()
Published Oct 1, 2013
4.0
MEDIUMCVSS 2.0
EPSS 11.41%
Description
Oracle MySQL and MariaDB 5.5.x before 5.5.29, 5.3.x before 5.3.12, and 5.2.x before 5.2.14 does not modify the salt during multiple executions of the change_user command within the same connection which makes it easier for remote authenticated users to conduct brute force password guessing attacks.
Affected products
No data.
No data.
Red Hat Enterprise Linux 5
mysql
Will not fix
Red Hat Enterprise Linux 6
mysql
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | mysql | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | mysql | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
References (11)
- http://seclists.org/fulldisclosure/2012/Dec/58 mailing-listx_refsource_FULLDISCExploitMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2012/Dec/83 mailing-listx_refsource_FULLDISCExploitMailing ListThird Party Advisory
- http://seclists.org/oss-sec/2012/q4/424 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://secunia.com/advisories/53372 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://security.gentoo.org/glsa/glsa-201308-06.xml vendor-advisoryx_refsource_GENTOOPatchThird Party AdvisoryVDB Entry
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:102 vendor-advisoryx_refsource_MANDRIVABroken Link
- https://access.redhat.com/security/cve/CVE-2012-5627 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=883719 x_refsource_MISCIssue TrackingPatchThird Party Advisory
- https://mariadb.atlassian.net/browse/MDEV-3915 x_refsource_CONFIRMBroken LinkVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2012-5627
- https://www.cve.org/CVERecord?id=CVE-2012-5627
Change history (0)
No recorded changes yet.