FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2012-5627

This CVE name corresponds to:

Entered Topic
2013-02-01 mysql/mariadb/percona server -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2012-5627
Phase Assigned(20121024)

Description

Oracle MySQL and MariaDB 5.5.x before 5.5.29, 5.3.x before 5.3.12, and 5.2.x before 5.2.14 does not modify the salt during multiple executions of the change_user command within the same connection which makes it easier for remote authenticated users to conduct brute force password guessing attacks.

References

Source Reference
FULLDISC 20121203 MySQL Local/Remote FAST Account Password Cracking
FULLDISC 20121205 Re: MySQL Local/Remote FAST Account Password Cracking
MLIST [oss-security] 20121206 Re: CVE request: Mysql/Mariadb insecure salt-usage
MISC https://bugzilla.redhat.com/show_bug.cgi?id=883719
CONFIRM https://mariadb.atlassian.net/browse/MDEV-3915
GENTOO GLSA-201308-06
MANDRIVA MDVSA-2013:102
SECUNIA 53372