Multiple SQL injection vulnerabilities in the replication code in Oracle MySQL possibly before 5.5.29, and MariaDB 5.1.x through 5.1.62, 5.2.x through 5.2.12, 5.3.x through 5.3.7, and 5.5.x through 5.5.25, allow remote authenticated users to execute arbitrary SQL commands via vectors related to the binary log. NOTE: as of 20130116, Oracle has not commented on claims from a downstream vendor that the fix in MySQL 5.5.29 is incomplete.
CVSS Details
- CVSS 3.1 Base Score: 6.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade percona-serverUpgrade mysql-serverUpgrade mariadb-server | Dec 10, 2025 | Feb 1, 2013 |
| Mariadb Mariadb | — | Upgrade MariaDB to the latest version | Mar 4, 2025 | Jan 22, 2013 |
| Oracle Mysql | — | Upgrade to Oracle MySQL version 5.5.29 | Jan 25, 2013 | Jan 22, 2013 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 11, 2012 |
| Suse | — | Upgrade mariadb104Upgrade libmariadb_pluginsUpgrade mariadb-toolsUpgrade liblz4-1Upgrade libmariadb-develUpgrade mariadb104-errormessagesUpgrade libmysqld-develUpgrade mariadb104-galeraUpgrade mariadb-errormessagesUpgrade mariadb-benchUpgrade libmariadbd19Upgrade mariadbUpgrade libmysqld19Upgrade mariadb104-toolsUpgrade libmariadb3Upgrade libmariadbd-develUpgrade libmariadbd104-develUpgrade mariadb104-rpm-macrosUpgrade mariadb104-clientUpgrade python3-mysqlclientUpgrade mariadb104-benchUpgrade mariadb104-testUpgrade mariadb-client | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade mysql-5.5Upgrade mysql-dfsg-5.1Upgrade mysql-5.1 | Nov 19, 2024 | Jan 22, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub