CVE-2012-5627 Information
Feb 14, 2021
cve
Description
Oracle MySQL and MariaDB 5.5.x before 5.5.29 5.3.x before 5.3.12 and 5.2.x before 5.2.14 does not modify the salt during multiple executions of the change_user command within the same connection which makes it easier for remote authenticated users to conduct brute force password guessing attacks.
Reference
http://seclists.org/fulldisclosure/2012/Dec/58 http://seclists.org/fulldisclosure/2012/Dec/83 http://seclists.org/oss-sec/2012/q4/424 http://secunia.com/advisories/53372 http://security.gentoo.org/glsa/glsa-201308-06.xml http://www.mandriva.com/security/advisories?name=MDVSA-2013:102 https://bugzilla.redhat.com/show_bug.cgi?id=883719 https://mariadb.atlassian.net/browse/MDEV-3915
Share on: