Bug 814287 (CVE-2012-1690) - CVE-2012-1690 mysql: unspecified DoS vulnerability related to Server Optimizer (CPU Apr 2012)
Summary: CVE-2012-1690 mysql: unspecified DoS vulnerability related to Server Optimize...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2012-1690
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 871813 871814
Blocks: 814308 mysql-cpu-2012-04
TreeView+ depends on / blocked
 
Reported: 2012-04-19 14:23 UTC by Jan Lieskovsky
Modified: 2019-09-29 12:52 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2014-01-21 15:14:56 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2012:1462 0 normal SHIPPED_LIVE Important: mysql security update 2012-11-15 01:51:48 UTC

Description Jan Lieskovsky 2012-04-19 14:23:15 UTC
Unspecified vulnerability in the server optimizer subcomponent of the Oracle MySQL server could allow authenticated database users to cause a hang or frequently repeatable crash of the MySQL server via multiple protocols.

Upstream announced, supported MySQL server versions, vulnerable to this flaw:
5.1.61 and earlier and 5.5.21 and earlier

References:
[1] http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html#AppendixMSQL
[2] http://www.oracle.com/technetwork/topics/security/cpuapr2012verbose-366316.html#Oracle%20MySQL

Comment 2 errata-xmlrpc 2012-11-14 20:53:01 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 6

Via RHSA-2012:1462 https://rhn.redhat.com/errata/RHSA-2012-1462.html


Note You need to log in before you can comment on or make changes to this bug.