FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2012-4414

This CVE name corresponds to:

Entered Topic
2013-02-01 mysql/mariadb/percona server -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2012-4414
Phase Assigned(20120821)

Description

Multiple SQL injection vulnerabilities in the replication code in Oracle MySQL possibly before 5.5.29, and MariaDB 5.1.x through 5.1.62, 5.2.x through 5.2.12, 5.3.x through 5.3.7, and 5.5.x through 5.5.25, allow remote authenticated users to execute arbitrary SQL commands via vectors related to the binary log. NOTE: as of 20130116, Oracle has not commented on claims from a downstream vendor that the fix in MySQL 5.5.29 is incomplete.

References

Source Reference
MLIST [oss-security] 20120911 Multiple SQL injections in MySQL/MariaDB
MISC http://bugs.mysql.com/bug.php?id=66550
MISC http://www.mysqlperformanceblog.com/2013/01/13/cve-2012-4414-in-mysql-5-5-29-and-percona-server-5-5-29/
CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=852144
CONFIRM https://mariadb.atlassian.net/browse/MDEV-382
MANDRIVA MDVSA-2013:150
MANDRIVA MDVSA-2013:102
SUSE openSUSE-SU-2013:0011
SUSE openSUSE-SU-2013:0014
SUSE openSUSE-SU-2013:0135
SUSE openSUSE-SU-2013:0156
BID 55498