CVE-2012-4414
Summary
| CVE | CVE-2012-4414 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-01-22 23:55:02 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Multiple SQL injection vulnerabilities in the replication code in Oracle MySQL possibly before 5.5.29, and MariaDB 5.1.x through 5.1.62, 5.2.x through 5.2.12, 5.3.x through 5.3.7, and 5.5.x through 5.5.25, allow remote authenticated users to execute arbitrary SQL commands via vectors related to the binary log. NOTE: as of 20130116, Oracle has not commented on claims from a downstream vendor that the fix in MySQL 5.5.29 is incomplete. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mariadb | Mariadb | 5.1.41 | All | All | All |
| Application | Mariadb | Mariadb | 5.1.42 | All | All | All |
| Application | Mariadb | Mariadb | 5.1.44 | All | All | All |
| Application | Mariadb | Mariadb | 5.1.47 | All | All | All |
| Application | Mariadb | Mariadb | 5.1.49 | All | All | All |
| Application | Mariadb | Mariadb | 5.1.50 | All | All | All |
| Application | Mariadb | Mariadb | 5.1.51 | All | All | All |
| Application | Mariadb | Mariadb | 5.1.53 | All | All | All |
| Application | Mariadb | Mariadb | 5.1.55 | All | All | All |
| Application | Mariadb | Mariadb | 5.1.60 | All | All | All |
| Application | Mariadb | Mariadb | 5.1.61 | All | All | All |
| Application | Mariadb | Mariadb | 5.1.62 | All | All | All |
| Application | Mariadb | Mariadb | 5.2.0 | All | All | All |
| Application | Mariadb | Mariadb | 5.2.1 | All | All | All |
| Application | Mariadb | Mariadb | 5.2.10 | All | All | All |
| Application | Mariadb | Mariadb | 5.2.11 | All | All | All |
| Application | Mariadb | Mariadb | 5.2.12 | All | All | All |
| Application | Mariadb | Mariadb | 5.2.2 | All | All | All |
| Application | Mariadb | Mariadb | 5.2.3 | All | All | All |
| Application | Mariadb | Mariadb | 5.2.4 | All | All | All |
| Application | Mariadb | Mariadb | 5.2.5 | All | All | All |
| Application | Mariadb | Mariadb | 5.2.6 | All | All | All |
| Application | Mariadb | Mariadb | 5.2.7 | All | All | All |
| Application | Mariadb | Mariadb | 5.2.8 | All | All | All |
| Application | Mariadb | Mariadb | 5.2.9 | All | All | All |
| Application | Mariadb | Mariadb | 5.3.0 | All | All | All |
| Application | Mariadb | Mariadb | 5.3.1 | All | All | All |
| Application | Mariadb | Mariadb | 5.3.2 | All | All | All |
| Application | Mariadb | Mariadb | 5.3.3 | All | All | All |
| Application | Mariadb | Mariadb | 5.3.4 | All | All | All |
| Application | Mariadb | Mariadb | 5.3.5 | All | All | All |
| Application | Mariadb | Mariadb | 5.3.6 | All | All | All |
| Application | Mariadb | Mariadb | 5.3.7 | All | All | All |
| Application | Mariadb | Mariadb | 5.5.20 | All | All | All |
| Application | Mariadb | Mariadb | 5.5.21 | All | All | All |
| Application | Mariadb | Mariadb | 5.5.22 | All | All | All |
| Application | Mariadb | Mariadb | 5.5.23 | All | All | All |
| Application | Mariadb | Mariadb | 5.5.24 | All | All | All |
| Application | Mariadb | Mariadb | 5.5.25 | All | All | All |
| Application | Oracle | Mysql | 5.1.51 | All | All | All |
| Application | Oracle | Mysql | 5.1.52 | All | All | All |
| Application | Oracle | Mysql | 5.1.52 | sp1 | All | All |
| Application | Oracle | Mysql | 5.1.53 | All | All | All |
| Application | Oracle | Mysql | 5.1.54 | All | All | All |
| Application | Oracle | Mysql | 5.1.55 | All | All | All |
| Application | Oracle | Mysql | 5.1.56 | All | All | All |
| Application | Oracle | Mysql | 5.1.57 | All | All | All |
| Application | Oracle | Mysql | 5.1.58 | All | All | All |
| Application | Oracle | Mysql | 5.1.59 | All | All | All |
| Application | Oracle | Mysql | 5.1.60 | All | All | All |
| Application | Oracle | Mysql | 5.1.61 | All | All | All |
| Application | Oracle | Mysql | 5.1.62 | All | All | All |
| Application | Oracle | Mysql | 5.1.63 | All | All | All |
| Application | Oracle | Mysql | 5.1.64 | All | All | All |
| Application | Oracle | Mysql | 5.1.65 | All | All | All |
| Application | Oracle | Mysql | 5.1.66 | All | All | All |
| Application | Oracle | Mysql | 5.1.67 | All | All | All |
| Application | Oracle | Mysql | 5.5.10 | All | All | All |
| Application | Oracle | Mysql | 5.5.11 | All | All | All |
| Application | Oracle | Mysql | 5.5.12 | All | All | All |
| Application | Oracle | Mysql | 5.5.13 | All | All | All |
| Application | Oracle | Mysql | 5.5.14 | All | All | All |
| Application | Oracle | Mysql | 5.5.15 | All | All | All |
| Application | Oracle | Mysql | 5.5.16 | All | All | All |
| Application | Oracle | Mysql | 5.5.17 | All | All | All |
| Application | Oracle | Mysql | 5.5.18 | All | All | All |
| Application | Oracle | Mysql | 5.5.19 | All | All | All |
| Application | Oracle | Mysql | 5.5.20 | All | All | All |
| Application | Oracle | Mysql | 5.5.21 | All | All | All |
| Application | Oracle | Mysql | 5.5.22 | All | All | All |
| Application | Oracle | Mysql | 5.5.23 | All | All | All |
| Application | Oracle | Mysql | 5.5.24 | All | All | All |
| Application | Oracle | Mysql | 5.5.25 | All | All | All |
| Application | Oracle | Mysql | 5.5.25 | a | All | All |
| Application | Oracle | Mysql | 5.5.26 | All | All | All |
| Application | Oracle | Mysql | 5.5.27 | All | All | All |
| Application | Oracle | Mysql | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [security-announce] openSUSE-SU-2013:0156-1: important: mariadb to 5.1.6 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| CVE-2012-4414 strikes back in MySQL 5.5.29 (and what we're doing in Percona Server 5.5.29) | af854a3a-2127-422b-91ae-364da2661108 | www.mysqlperformanceblog.com | |
| [MDEV-382] Multiple SQL injection vulnerabilities in the replication code - JIRA | af854a3a-2127-422b-91ae-364da2661108 | mariadb.atlassian.net | |
| [security-announce] openSUSE-SU-2013:0135-1: important: mysql-community- | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| 852144 – (CVE-2012-4414) CVE-2012-4414 mysql: Multiple SQL injection flaws by generation of binlog entries | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| MariaDB CVE-2012-4414 Multiple SQL Injection Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| [security-announce] openSUSE-SU-2013:0011-1: important: mariadb to 5.5.2 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| [security-announce] openSUSE-SU-2013:0014-1: important: mariadb to 5.2.1 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| MySQL Bugs: Access denied | af854a3a-2127-422b-91ae-364da2661108 | bugs.mysql.com | |
| Support / Security / Advisories / / MDVSA-2013:150 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Support / Security / Advisories / / MDVSA-2013:102 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| oss-security - Multiple SQL injections in MySQL/MariaDB | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.