Oracle MySQL and MariaDB 5.5.x before 5.5.29, 5.3.x before 5.3.12, and 5.2.x before 5.2.14 does not modify the salt during multiple executions of the change_user command within the same connection which makes it easier for remote authenticated users to conduct brute force password guessing attacks.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade percona-serverUpgrade mariadb-serverUpgrade mysql-server | Dec 10, 2025 | Feb 1, 2013 |
| Gentoo Linux | — | Upgrade dev-db/mysql. | Oct 30, 2017 | Oct 1, 2013 |
| Mariadb Mariadb | — | Upgrade MariaDB to the latest version | Mar 4, 2025 | Oct 1, 2013 |
| Oracle Mysql | — | Upgrade to Oracle MySQL version 5.2.14Upgrade to Oracle MySQL version 5.5.29Upgrade to Oracle MySQL version 5.3.12 | May 9, 2019 | Oct 1, 2013 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Dec 3, 2012 |
| Suse | — | Upgrade mariadb-clientUpgrade libmariadbd104-develUpgrade libmysqld19Upgrade mariadb104-testUpgrade libmariadbd-develUpgrade libmariadbd19Upgrade mariadb-benchUpgrade mariadb104-clientUpgrade mariadb104-galeraUpgrade libmariadb3Upgrade libmysqld-develUpgrade libmariadb-develUpgrade libmariadb_pluginsUpgrade mariadb104Upgrade mariadb-toolsUpgrade mariadb104-rpm-macrosUpgrade mariadbUpgrade mariadb104-benchUpgrade mariadb104-errormessagesUpgrade mariadb104-toolsUpgrade mariadb-errormessagesUpgrade liblz4-1Upgrade python3-mysqlclient | Aug 9, 2024 | Jul 9, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub