Bug 867230 (CVE-2012-3167)

Summary: CVE-2012-3167 mysql: unspecified DoS vulnerability related to Server Full Text Search (CPU Oct 2012)
Product: [Other] Security Response Reporter: Kurt Seifried <kseifried>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: byte, hhorak, rmillner, tkramer
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2013-11-06 18:46:03 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 871813, 871814    
Bug Blocks: 867241, 870399    

Description Kurt Seifried 2012-10-17 06:04:21 UTC
Common Vulnerabilities and Exposures assigned an identifier CVE-2012-3167 to
the following vulnerability:

Name: CVE-2012-3167
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3167
Assigned: 20120606
Reference: http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html

Unspecified vulnerability in the MySQL Server component in Oracle
MySQL 5.1.63 and earlier, and 5.5.25 and earlier, allows remote
authenticated users to affect availability via unknown vectors related
to Server Full Text Search.

Comment 2 errata-xmlrpc 2012-11-14 20:56:42 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 6

Via RHSA-2012:1462 https://rhn.redhat.com/errata/RHSA-2012-1462.html

Comment 3 Vincent Danen 2013-11-06 18:46:03 UTC
Statement:

On Red Hat Enterprise Linux 5.10, new MySQL 5.5 packages are available which are not vulnerable to this issue.  Future updates for MySQL 5.0 will no longer be made available (mysql-5.0.* and related packages); security advisories will be provided only for MySQL 5.5.  Please refer to https://rhn.redhat.com/errata/RHEA-2013-1330.html for further information.