Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2012-2122


sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x before 5.1.62, 5.2.x before 5.2.12, 5.3.x before 5.3.6, and 5.5.x before 5.5.23, when running in certain environments with certain implementations of the memcmp function, allows remote attackers to bypass authentication by repeatedly authenticating with the same incorrect password, which eventually causes a token comparison to succeed due to an improperly-checked return value.


Published

2012-06-26T18:55:05.083

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 5.1 (MEDIUM)

CVSSv2 Vector

AV:N/AC:H/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: HIGH
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

4.9

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-287

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application oracle mysql 5.1.51 Yes
Application oracle mysql 5.1.52 Yes
Application oracle mysql 5.1.52 Yes
Application oracle mysql 5.1.53 Yes
Application oracle mysql 5.1.54 Yes
Application oracle mysql 5.1.55 Yes
Application oracle mysql 5.1.56 Yes
Application oracle mysql 5.1.57 Yes
Application oracle mysql 5.1.58 Yes
Application oracle mysql 5.1.59 Yes
Application oracle mysql 5.1.60 Yes
Application oracle mysql 5.1.61 Yes
Application oracle mysql 5.5.10 Yes
Application oracle mysql 5.5.11 Yes
Application oracle mysql 5.5.12 Yes
Application oracle mysql 5.5.13 Yes
Application oracle mysql 5.5.14 Yes
Application oracle mysql 5.5.15 Yes
Application oracle mysql 5.5.16 Yes
Application oracle mysql 5.5.17 Yes
Application oracle mysql 5.5.18 Yes
Application oracle mysql 5.5.19 Yes
Application oracle mysql 5.5.20 Yes
Application oracle mysql 5.5.21 Yes
Application oracle mysql 5.6.2 Yes
Application oracle mysql 5.6.3 Yes
Application oracle mysql 5.6.4 Yes
Application oracle mysql 5.6.5 Yes
Application mariadb mariadb 5.1.41 Yes
Application mariadb mariadb 5.1.42 Yes
Application mariadb mariadb 5.1.44 Yes
Application mariadb mariadb 5.1.47 Yes
Application mariadb mariadb 5.1.49 Yes
Application mariadb mariadb 5.1.50 Yes
Application mariadb mariadb 5.1.51 Yes
Application mariadb mariadb 5.1.53 Yes
Application mariadb mariadb 5.1.55 Yes
Application mariadb mariadb 5.1.60 Yes
Application mariadb mariadb 5.1.61 Yes
Application mariadb mariadb 5.2.0 Yes
Application mariadb mariadb 5.2.1 Yes
Application mariadb mariadb 5.2.2 Yes
Application mariadb mariadb 5.2.3 Yes
Application mariadb mariadb 5.2.4 Yes
Application mariadb mariadb 5.2.5 Yes
Application mariadb mariadb 5.2.6 Yes
Application mariadb mariadb 5.2.7 Yes
Application mariadb mariadb 5.2.8 Yes
Application mariadb mariadb 5.2.9 Yes
Application mariadb mariadb 5.2.10 Yes
Application mariadb mariadb 5.2.11 Yes
Application mariadb mariadb 5.3.0 Yes
Application mariadb mariadb 5.3.1 Yes
Application mariadb mariadb 5.3.2 Yes
Application mariadb mariadb 5.3.3 Yes
Application mariadb mariadb 5.3.4 Yes
Application mariadb mariadb 5.3.5 Yes
Application mariadb mariadb 5.3.6 Yes
Application mariadb mariadb 5.5.20 Yes
Application mariadb mariadb 5.5.21 Yes
Application mariadb mariadb 5.5.22 Yes

References