MariaDB 5.5.x before 5.5.30, 5.3.x before 5.3.13, 5.2.x before 5.2.15, and 5.1.x before 5.1.68, and Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote attackers to cause a denial of service (crash) via a crafted geometry feature that specifies a large number of points, which is not properly handled when processing the binary representation of this feature, related to a numeric calculation error.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade mysql. | Aug 30, 2017 | Mar 28, 2013 |
| Gentoo Linux | — | Upgrade dev-db/mysql. | Oct 30, 2017 | Mar 28, 2013 |
| Mariadb Mariadb | — | Upgrade MariaDB to the latest version | Mar 4, 2025 | Mar 28, 2013 |
| Oracle Mysql | — | Upgrade to Oracle MySQL version 5.1.68Upgrade to Oracle MySQL version 5.2.15Upgrade to Oracle MySQL version 5.3.13Upgrade to Oracle MySQL version 5.5.30 | Aug 8, 2022 | Mar 28, 2013 |
| Oracle Solaris | — | Upgrade database/mysql-51/tests to version 5.1.37-0.175.1.10.0.5.0 on Solaris 11.1Upgrade database/mysql-51/library to version 5.1.37-0.175.1.10.0.5.0 on Solaris 11.1Upgrade database/mysql-51 to version 5.1.37-0.175.1.10.0.5.0 on Solaris 11.1 | May 29, 2017 | Mar 28, 2013 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 5, 2013 |
| Suse | — | Upgrade mysql-clientUpgrade libmysql55client18-x86Upgrade mysql-toolsUpgrade libmysql55client_r18-32bitUpgrade libmysqlclient15-x86Upgrade libmysql55client18Upgrade libmysqlclient15-32bitUpgrade libmysqlclient_r15-32bitUpgrade libmysql55client_r18Upgrade libmysqlclient_r15Upgrade mysqlUpgrade libmysql55client18-32bitUpgrade SLES-for-VMware-releaseUpgrade libmysqlclient15 | Feb 17, 2015 | Mar 28, 2013 |
| Ubuntu | — | Upgrade mysql-server-5.5Upgrade mysql-server-5.1 | Nov 8, 2024 | Mar 28, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub