sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x before 5.1.62, 5.2.x before 5.2.12, 5.3.x before 5.3.6, and 5.5.x before 5.5.23, when running in certain environments with certain implementations of the memcmp function, allows remote attackers to bypass authentication by repeatedly authenticating with the same incorrect password, which eventually causes a token comparison to succeed due to an improperly-checked return value.
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade mysql. | Aug 30, 2017 | May 3, 2012 |
| Gentoo Linux | — | Upgrade dev-db/mysql. | Oct 30, 2017 | Jun 26, 2012 |
| Mysql | — | — | Jun 19, 2012 | Jun 9, 2012 |
| Oracle Mysql | — | Upgrade to Oracle MySQL version 5.1.63Upgrade to Oracle MySQL version 5.5.24Upgrade to Oracle MySQL version 5.6.6 | Aug 26, 2012 | Jun 26, 2012 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 9, 2012 |
| Suse | — | Upgrade libmysqlclient15Upgrade libmysqlclient_r15-32bitUpgrade libmysqlclient15-32bitUpgrade libmysqlclient15-x86Upgrade mysqlUpgrade mysql-clientUpgrade libmysql55client18Upgrade mysql-toolsUpgrade libmysql55client_r18-32bitUpgrade libmysql55client18-32bitUpgrade libmysql55client18-x86Upgrade libmysql55client_r18-x86Upgrade libmysqlclient_r15Upgrade libmysqlclient-develUpgrade libmysql55client_r18Upgrade libmysqlclient_r15-x86 | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade mysql-server-5.1Upgrade mysql-server-5.0Upgrade mysql-server-5.5 | Nov 8, 2024 | Jun 26, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub