{"api_version":"1","generated_at":"2026-07-23T11:04:53+00:00","cve":"CVE-2012-5612","urls":{"html":"https://cve.report/CVE-2012-5612","api":"https://cve.report/api/cve/CVE-2012-5612.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2012-5612","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2012-5612"},"summary":{"title":"CVE-2012-5612","description":"Heap-based buffer overflow in Oracle MySQL 5.5.19 and other versions through 5.5.28, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code, as demonstrated using certain variations of the (1) USE, (2) SHOW TABLES, (3) DESCRIBE, (4) SHOW FIELDS FROM, (5) SHOW COLUMNS FROM, (6) SHOW INDEX FROM, (7) CREATE TABLE, (8) DROP TABLE, (9) ALTER TABLE, (10) DELETE FROM, (11) UPDATE, and (12) SET PASSWORD commands.","state":"PUBLISHED","assigner":"redhat","published_at":"2012-12-03 12:49:43","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-787","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.5","severity":"","vector":"AV:N/AC:L/Au:S/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://security.gentoo.org/glsa/glsa-201308-06.xml","name":"http://security.gentoo.org/glsa/glsa-201308-06.xml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Gentoo Linux Documentation\n--\n  MySQL: Multiple vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16960","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16960","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2012/12/02/4","name":"http://www.openwall.com/lists/oss-security/2012/12/02/4","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"oss-security - Re: Re: [Full-disclosure] MySQL (Linux) Stack based\n buffer overrun PoC Zeroday","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html","name":"http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Oracle Critical Patch Update - January 2013","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://mariadb.atlassian.net/browse/MDEV-3908","name":"https://mariadb.atlassian.net/browse/MDEV-3908","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Exploit","Patch"],"title":"[MDEV-3908] crash in multi-table delete and mdl - JIRA","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2012/12/02/3","name":"http://www.openwall.com/lists/oss-security/2012/12/02/3","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"oss-security - Re: Re: [Full-disclosure] MySQL (Linux) Stack based\n buffer overrun PoC Zeroday","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ubuntu.com/usn/USN-1703-1","name":"http://www.ubuntu.com/usn/USN-1703-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"USN-1703-1: MySQL vulnerabilities | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://seclists.org/fulldisclosure/2012/Dec/5","name":"http://seclists.org/fulldisclosure/2012/Dec/5","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Mailing List","Third Party Advisory"],"title":"Full Disclosure: MySQL (Linux) Heap Based Overrun PoC Zeroday","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00000.html","name":"http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00000.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[security-announce] SUSE-SU-2013:0262-1: important: Security update for","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2013:150","name":"http://www.mandriva.com/security/advisories?name=MDVSA-2013:150","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Support / Security / Advisories /  / MDVSA-2013:150 | Mandriva","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2013:102","name":"http://www.mandriva.com/security/advisories?name=MDVSA-2013:102","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Support / Security / Advisories /  / MDVSA-2013:102 | Mandriva","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/53372","name":"http://secunia.com/advisories/53372","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Not Applicable"],"title":"About Secunia Research | Flexera","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://www.exploit-db.com/exploits/23076","name":"http://www.exploit-db.com/exploits/23076","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory","VDB Entry"],"title":"MySQL (Linux) Heap Based Overrun PoC Zeroday","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2012-5612","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2012-5612","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2012","cve_id":"5612","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mariadb","cpe5":"mariadb","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T21:14:15.937Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"23076","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"http://www.exploit-db.com/exploits/23076"},{"name":"20121201 MySQL (Linux) Heap Based Overrun PoC Zeroday","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://seclists.org/fulldisclosure/2012/Dec/5"},{"name":"USN-1703-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/USN-1703-1"},{"name":"MDVSA-2013:102","tags":["vendor-advisory","x_refsource_MANDRIVA","x_transferred"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2013:102"},{"name":"53372","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/53372"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html"},{"name":"[oss-security] 20121202 Re: Re: [Full-disclosure] MySQL (Linux) Stack based  buffer overrun PoC Zeroday","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2012/12/02/3"},{"name":"GLSA-201308-06","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"http://security.gentoo.org/glsa/glsa-201308-06.xml"},{"name":"[oss-security] 20121202 Re: Re: [Full-disclosure] MySQL (Linux) Stack based  buffer overrun PoC Zeroday","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2012/12/02/4"},{"name":"SUSE-SU-2013:0262","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00000.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://mariadb.atlassian.net/browse/MDEV-3908"},{"name":"oval:org.mitre.oval:def:16960","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16960"},{"name":"MDVSA-2013:150","tags":["vendor-advisory","x_refsource_MANDRIVA","x_transferred"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2013:150"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2012-12-01T00:00:00.000Z","descriptions":[{"lang":"en","value":"Heap-based buffer overflow in Oracle MySQL 5.5.19 and other versions through 5.5.28, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code, as demonstrated using certain variations of the (1) USE, (2) SHOW TABLES, (3) DESCRIBE, (4) SHOW FIELDS FROM, (5) SHOW COLUMNS FROM, (6) SHOW INDEX FROM, (7) CREATE TABLE, (8) DROP TABLE, (9) ALTER TABLE, (10) DELETE FROM, (11) UPDATE, and (12) SET PASSWORD commands."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-18T12:57:01.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"name":"23076","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"http://www.exploit-db.com/exploits/23076"},{"name":"20121201 MySQL (Linux) Heap Based Overrun PoC Zeroday","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://seclists.org/fulldisclosure/2012/Dec/5"},{"name":"USN-1703-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/USN-1703-1"},{"name":"MDVSA-2013:102","tags":["vendor-advisory","x_refsource_MANDRIVA"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2013:102"},{"name":"53372","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/53372"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html"},{"name":"[oss-security] 20121202 Re: Re: [Full-disclosure] MySQL (Linux) Stack based  buffer overrun PoC Zeroday","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2012/12/02/3"},{"name":"GLSA-201308-06","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"http://security.gentoo.org/glsa/glsa-201308-06.xml"},{"name":"[oss-security] 20121202 Re: Re: [Full-disclosure] MySQL (Linux) Stack based  buffer overrun PoC Zeroday","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2012/12/02/4"},{"name":"SUSE-SU-2013:0262","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00000.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://mariadb.atlassian.net/browse/MDEV-3908"},{"name":"oval:org.mitre.oval:def:16960","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16960"},{"name":"MDVSA-2013:150","tags":["vendor-advisory","x_refsource_MANDRIVA"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2013:150"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secalert@redhat.com","ID":"CVE-2012-5612","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Heap-based buffer overflow in Oracle MySQL 5.5.19 and other versions through 5.5.28, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code, as demonstrated using certain variations of the (1) USE, (2) SHOW TABLES, (3) DESCRIBE, (4) SHOW FIELDS FROM, (5) SHOW COLUMNS FROM, (6) SHOW INDEX FROM, (7) CREATE TABLE, (8) DROP TABLE, (9) ALTER TABLE, (10) DELETE FROM, (11) UPDATE, and (12) SET PASSWORD commands."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"23076","refsource":"EXPLOIT-DB","url":"http://www.exploit-db.com/exploits/23076"},{"name":"20121201 MySQL (Linux) Heap Based Overrun PoC Zeroday","refsource":"FULLDISC","url":"http://seclists.org/fulldisclosure/2012/Dec/5"},{"name":"USN-1703-1","refsource":"UBUNTU","url":"http://www.ubuntu.com/usn/USN-1703-1"},{"name":"MDVSA-2013:102","refsource":"MANDRIVA","url":"http://www.mandriva.com/security/advisories?name=MDVSA-2013:102"},{"name":"53372","refsource":"SECUNIA","url":"http://secunia.com/advisories/53372"},{"name":"http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html","refsource":"CONFIRM","url":"http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html"},{"name":"[oss-security] 20121202 Re: Re: [Full-disclosure] MySQL (Linux) Stack based  buffer overrun PoC Zeroday","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2012/12/02/3"},{"name":"GLSA-201308-06","refsource":"GENTOO","url":"http://security.gentoo.org/glsa/glsa-201308-06.xml"},{"name":"[oss-security] 20121202 Re: Re: [Full-disclosure] MySQL (Linux) Stack based  buffer overrun PoC Zeroday","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2012/12/02/4"},{"name":"SUSE-SU-2013:0262","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00000.html"},{"name":"https://mariadb.atlassian.net/browse/MDEV-3908","refsource":"CONFIRM","url":"https://mariadb.atlassian.net/browse/MDEV-3908"},{"name":"oval:org.mitre.oval:def:16960","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16960"},{"name":"MDVSA-2013:150","refsource":"MANDRIVA","url":"http://www.mandriva.com/security/advisories?name=MDVSA-2013:150"}]}}}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2012-5612","datePublished":"2012-12-03T11:00:00.000Z","dateReserved":"2012-10-24T00:00:00.000Z","dateUpdated":"2024-08-06T21:14:15.937Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2012-12-03 12:49:43","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-787","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*","versionStartIncluding":"5.1.0","versionEndExcluding":"5.1.67","matchCriteriaId":"88ED7479-C3D3-41F5-B6A3-06F6A699CD19"},{"vulnerable":true,"criteria":"cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2.0","versionEndExcluding":"5.2.14","matchCriteriaId":"F26667EE-39AA-4BA1-B40D-37FBCB43B50B"},{"vulnerable":true,"criteria":"cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*","versionStartIncluding":"5.3.0","versionEndExcluding":"5.3.12","matchCriteriaId":"607658C7-318E-489B-926C-0B818EA172F0"},{"vulnerable":true,"criteria":"cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*","versionStartIncluding":"5.5.0","versionEndExcluding":"5.5.29","matchCriteriaId":"9B845EAE-A675-4A46-A01C-0F8C253EE7ED"},{"vulnerable":true,"criteria":"cpe:2.3:a:mariadb:mariadb:10.0.0:*:*:*:*:*:*:*","matchCriteriaId":"3553190A-1EA3-4FDC-838C-1AF34A0D5D1A"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*","versionStartIncluding":"5.5.0","versionEndIncluding":"5.5.28","matchCriteriaId":"82736F72-072A-47E7-828D-8B95B257C4A8"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:suse:linux_enterprise_desktop:11:sp2:*:*:*:*:*:*","matchCriteriaId":"00720D8C-3FF3-4B1C-B74B-91F01A544399"},{"vulnerable":true,"criteria":"cpe:2.3:o:suse:linux_enterprise_server:11:sp2:*:*:*:-:*:*","matchCriteriaId":"88D6E858-FD8F-4C55-B7D5-CEEDA2BBA898"},{"vulnerable":true,"criteria":"cpe:2.3:o:suse:linux_enterprise_server:11:sp2:*:*:*:vmware:*:*","matchCriteriaId":"DB4D6749-81A1-41D7-BF4F-1C45A7F49A22"},{"vulnerable":true,"criteria":"cpe:2.3:o:suse:linux_enterprise_software_development_kit:11:sp2:*:*:*:*:*:*","matchCriteriaId":"5AA37837-3083-4DC7-94F4-54FD5D7CB53C"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:*","matchCriteriaId":"01EDA41C-6B2E-49AF-B503-EB3882265C11"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:11.10:*:*:*:*:*:*:*","matchCriteriaId":"E4174F4F-149E-41A6-BBCC-D01114C05F38"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*","matchCriteriaId":"CB66DB75-2B16-4EBF-9B93-CE49D8086E41"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*","matchCriteriaId":"E2076871-2E80-4605-A470-A41C1A8EC7EE"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2012","CveId":"5612","Ordinal":"1","Title":"CVE-2012-5612","CVE":"CVE-2012-5612","Year":"2012"},"notes":[{"CveYear":"2012","CveId":"5612","Ordinal":"1","NoteData":"Heap-based buffer overflow in Oracle MySQL 5.5.19 and other versions through 5.5.28, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code, as demonstrated using certain variations of the (1) USE, (2) SHOW TABLES, (3) DESCRIBE, (4) SHOW FIELDS FROM, (5) SHOW COLUMNS FROM, (6) SHOW INDEX FROM, (7) CREATE TABLE, (8) DROP TABLE, (9) ALTER TABLE, (10) DELETE FROM, (11) UPDATE, and (12) SET PASSWORD commands.","Type":"Description","Title":"CVE-2012-5612"},{"CveYear":"2012","CveId":"5612","Ordinal":"2","NoteData":"2012-12-03","Type":"Other","Title":"Published"},{"CveYear":"2012","CveId":"5612","Ordinal":"3","NoteData":"2017-09-18","Type":"Other","Title":"Modified"}]}}}