Bug 867230 (CVE-2012-3167)

Summary: CVE-2012-3167 mysql: unspecified DoS vulnerability related to Server Full Text Search (CPU Oct 2012)
Product: [Other] Security Response Reporter: Kurt Seifried <kseifried>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: byte, hhorak, rmillner, tkramer
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: impact=low,public=20121016,reported=20121016,source=internet,cvss2=3.5/AV:N/AC:M/Au:S/C:N/I:N/A:P,rhel-5/mysql=new,rhel-6/mysql=affected,fedora-all/mysql=affected,openshift-1/mysql=affected
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2013-11-06 13:46:03 EST Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Bug Depends On: 871813, 871814    
Bug Blocks: 867241, 870399    

Description Kurt Seifried 2012-10-17 02:04:21 EDT
Common Vulnerabilities and Exposures assigned an identifier CVE-2012-3167 to
the following vulnerability:

Name: CVE-2012-3167
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3167
Assigned: 20120606
Reference: http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html

Unspecified vulnerability in the MySQL Server component in Oracle
MySQL 5.1.63 and earlier, and 5.5.25 and earlier, allows remote
authenticated users to affect availability via unknown vectors related
to Server Full Text Search.
Comment 2 errata-xmlrpc 2012-11-14 15:56:42 EST
This issue has been addressed in following products:

  Red Hat Enterprise Linux 6

Via RHSA-2012:1462 https://rhn.redhat.com/errata/RHSA-2012-1462.html
Comment 3 Vincent Danen 2013-11-06 13:46:03 EST
Statement:

On Red Hat Enterprise Linux 5.10, new MySQL 5.5 packages are available which are not vulnerable to this issue.  Future updates for MySQL 5.0 will no longer be made available (mysql-5.0.* and related packages); security advisories will be provided only for MySQL 5.5.  Please refer to https://rhn.redhat.com/errata/RHEA-2013-1330.html for further information.