CVE-2012-5614

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/12/2012
Last modified:
11/04/2025

Description

Oracle MySQL 5.1.67 and earlier and 5.5.29 and earlier, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a denial of service (mysqld crash) via a SELECT command with an UpdateXML command containing XML with a large number of unique, nested elements.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:* 5.1.0 (including) 5.1.67 (including)
cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:* 5.5.0 (including) 5.5.29 (including)
cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:* 5.5.0 (including) 5.5.30 (excluding)
cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:* 10.0.0 (including) 10.0.2 (excluding)
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:6.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:6.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*