Oracle MySQL 5.1.67 and earlier and 5.5.29 and earlier, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a denial of service (mysqld crash) via a SELECT command with an UpdateXML command containing XML with a large number of unique, nested elements.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade mysql-testUpgrade mysqlUpgrade mysql-benchUpgrade mysql-embeddedUpgrade mysql-serverUpgrade mysql-develUpgrade mysql-libsUpgrade mysql-embedded-devel | Dec 1, 2016 | Dec 3, 2012 |
| Gentoo Linux | — | Upgrade dev-db/mysql. | Oct 30, 2017 | Dec 3, 2012 |
| Mariadb Mariadb | — | Upgrade MariaDB to the latest version | Mar 4, 2025 | Dec 3, 2012 |
| Oracle Mysql | — | Upgrade to the latest version of MySQL | Apr 16, 2013 | Dec 3, 2012 |
| Oracle_linux | — | Upgrade mysql-embedded-develUpgrade mysql-serverUpgrade mysql-embeddedUpgrade mysql-develUpgrade mysql-benchUpgrade mysqlUpgrade mysql-testUpgrade mysql-libs | Oct 16, 2024 | Dec 3, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub