sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x before 5.1.62, 5.2.x before 5.2.12, 5.3.x before 5.3.6, and 5.5.x before 5.5.23, when running in certain environments with certain implementations of the memcmp function, allows remote attackers to bypass authentication by repeatedly authenticating with the same incorrect password, which eventually causes a token comparison to succeed due to an improperly-checked return value.
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade mysql. | Aug 30, 2017 | May 3, 2012 |
| Gentoo Linux | — | Upgrade dev-db/mysql. | Oct 30, 2017 | Jun 26, 2012 |
| Mysql | — | — | Jun 19, 2012 | Jun 9, 2012 |
| Oracle Mysql | — | Upgrade to Oracle MySQL version 5.6.6Upgrade to Oracle MySQL version 5.1.63Upgrade to Oracle MySQL version 5.5.24 | Aug 26, 2012 | Jun 26, 2012 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 9, 2012 |
| Suse | — | Upgrade mysqlUpgrade mysql-clientUpgrade libmysqlclient_r15-32bitUpgrade libmysqlclient15-x86Upgrade libmysqlclient15Upgrade mysql-toolsUpgrade libmysqlclient15-32bitUpgrade libmysql55client18Upgrade libmysql55client_r18-32bitUpgrade libmysql55client_r18Upgrade libmysqlclient_r15-x86Upgrade libmysqlclient_r15Upgrade libmysql55client_r18-x86Upgrade libmysql55client18-x86Upgrade libmysqlclient-develUpgrade libmysql55client18-32bit | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade mysql-server-5.5Upgrade mysql-server-5.0Upgrade mysql-server-5.1 | Nov 8, 2024 | Jun 26, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub