CVE-2012-5627
Summary
| CVE | CVE-2012-5627 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-10-01 17:55:03 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Oracle MySQL and MariaDB 5.5.x before 5.5.29, 5.3.x before 5.3.12, and 5.2.x before 5.2.14 does not modify the salt during multiple executions of the change_user command within the same connection which makes it easier for remote authenticated users to conduct brute force password guessing attacks. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:S/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Gentoo Linux Documentation -- MySQL: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | Patch, Third Party Advisory, VDB Entry |
| Full Disclosure: Re: MySQL Local/Remote FAST Account Password Cracking | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | Exploit, Mailing List, Third Party Advisory |
| oss-sec: Re: CVE request: Mysql/Mariadb insecure salt-usage | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | Mailing List, Third Party Advisory |
| Full Disclosure: MySQL Local/Remote FAST Account Password Cracking | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | Exploit, Mailing List, Third Party Advisory |
| Support / Security / Advisories / / MDVSA-2013:102 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | Broken Link |
| Bug 883719 – CVE-2012-5627 mysql: efficient password guessing attack using change_user() | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Issue Tracking, Patch, Third Party Advisory |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Not Applicable |
| [#MDEV-3915] COM_CHANGE_USER allows fast password brute-forcing - JIRA | af854a3a-2127-422b-91ae-364da2661108 | mariadb.atlassian.net | Broken Link, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 900276 CBL-Mariner Linux Security Update for mysql 8.0.24
- 900307 CBL-Mariner Linux Security Update for mysql 8.0.26
- 901561 Common Base Linux Mariner (CBL-Mariner) Security Update for mysql (6692-1)
- 903310 Common Base Linux Mariner (CBL-Mariner) Security Update for mysql (2669)
- 906168 Common Base Linux Mariner (CBL-Mariner) Security Update for mysql (2669-1)
- 906449 Common Base Linux Mariner (CBL-Mariner) Security Update for mysql (6692-2)