Bug 867217 (CVE-2012-3173)

Summary: CVE-2012-3173 mysql: unspecified DoS vulnerability related to InnoDB Plugin (CPU Oct 2012)
Product: [Other] Security Response Reporter: Kurt Seifried <kseifried>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: byte, hhorak, kvolny, rmillner, tgl, tkramer
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2012-11-15 07:47:09 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 871813, 871814    
Bug Blocks: 867241, 870399    

Description Kurt Seifried 2012-10-17 05:34:41 UTC
Common Vulnerabilities and Exposures assigned an identifier CVE-2012-3173 to
the following vulnerability:

Name: CVE-2012-3173
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3173
Assigned: 20120606
Reference: http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html

Unspecified vulnerability in the MySQL Server component in Oracle
MySQL 5.1.63 and earlier, and 5.5.25 and earlier, allows remote
authenticated users to affect availability via unknown vectors related
to InnoDB Plugin.

Comment 1 Tomas Hoger 2012-11-02 13:27:15 UTC
InnoDB plugin was first enabled in MySQL packages in Red Hat Enterprise Linux 6 via Red Hat Enterprise Linux 6.3 erratum RHSA-2012:0874:

  https://rhn.redhat.com/errata/RHSA-2012-0874.html

InnoDB plugin is only available on x86 and x86_64 platforms.

MySQL 5.0 packages in Red Hat Enterprise Linux 5 do not include InnoDB plugin.

Comment 3 errata-xmlrpc 2012-11-14 20:53:36 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 6

Via RHSA-2012:1462 https://rhn.redhat.com/errata/RHSA-2012-1462.html