CVE-2013-1861
Summary
| CVE | CVE-2013-1861 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-03-28 23:55:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | MariaDB 5.5.x before 5.5.30, 5.3.x before 5.3.13, 5.2.x before 5.2.15, and 5.1.x before 5.1.68, and Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote attackers to cause a denial of service (crash) via a crafted geometry feature that specifies a large number of points, which is not properly handled when processing the binary representation of this feature, related to a numeric calculation error. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:L/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [Commits] Rev 3682: TODO-424 geometry query crashes server. in file:///home/hf/wmar/todo-424/ | af854a3a-2127-422b-91ae-364da2661108 | lists.askmonty.org | Mailing List, Third Party Advisory |
| MySQL and MariaDB Geometry Query Denial Of Service Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit, Third Party Advisory, VDB Entry |
| [security-announce] SUSE-SU-2013:1390-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Mailing List, Third Party Advisory |
| oss-sec: CVE-2013-1861 for MySQL/MariaDB: geometry query crashes mysqld | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | Mailing List, Third Party Advisory |
| Bug 919247 – CVE-2013-1861 mysql: geometry query crashes mysqld (CPU July 2013) | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Issue Tracking, Third Party Advisory |
| Security Advisory SA54300 - Ubuntu update for mysql - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Not Applicable |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Not Applicable |
| openSUSE-SU-2013:1335-1: moderate: update for mariadb, mysql-community-s | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Mailing List, Third Party Advisory |
| Oracle Critical Patch Update - July 2013 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Third Party Advisory |
| USN-1909-1: MySQL vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | Third Party Advisory |
| www.osvdb.org/91415 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | Broken Link |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| [security-announce] SUSE-SU-2013:1529-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Mailing List, Third Party Advisory |
| Debian -- Security Information -- DSA-2818-1 mysql-5.5 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Third Party Advisory |
| [MDEV-4252] geometry query crashes server - JIRA | af854a3a-2127-422b-91ae-364da2661108 | mariadb.atlassian.net | Broken Link |
| Gentoo Linux Documentation -- MySQL: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | Third Party Advisory |
| openSUSE-SU-2013:1410-1: moderate: update for mysql-community-server | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.