Bug 852144 (CVE-2012-4414) - CVE-2012-4414 mysql: Multiple SQL injection flaws by generation of binlog entries
Summary: CVE-2012-4414 mysql: Multiple SQL injection flaws by generation of binlog ent...
Keywords:
Status: NEW
Alias: CVE-2012-4414
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
: 855539 (view as bug list)
Depends On: 863320
Blocks: 852149
TreeView+ depends on / blocked
 
Reported: 2012-08-27 17:30 UTC by Jan Lieskovsky
Modified: 2019-09-29 12:55 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed:


Attachments (Terms of Use)

Description Jan Lieskovsky 2012-08-27 17:30:40 UTC
Multiple SQL injection flaws were found in the way the binlog functionality (routines producing events describing database changes such as table creation operations or changes to table data) of MySQL, a multi-user, multi-threaded SQL database server, performed sanitization of table names and other fields prior creating particular log entry. Authorised database users (with privilege to modify tables) could use this flaw to inject arbitrary SQL query into subsequently generated binlog entries.

References:
[1] https://mariadb.atlassian.net/browse/MDEV-382

MariaDB patches:
[2] http://bazaar.launchpad.net/~maria-captains/maria/5.1/revision/3151.1.1
    (against 5.1 branch)
[3] http://bazaar.launchpad.net/~maria-captains/maria/5.2/revision/3163.1.1
    (against 5.2 branch)
[4] http://bazaar.launchpad.net/~maria-captains/maria/5.3/revision/3556.1.2
    (against 5.3 branch)
[5] http://bazaar.launchpad.net/~maria-captains/maria/5.5/revision/3508
    (against 5.5 branch)

MySQL bug:
[6] http://bugs.mysql.com/66550

Comment 10 Kurt Seifried 2012-09-08 19:50:33 UTC
*** Bug 855539 has been marked as a duplicate of this bug. ***

Comment 11 Kurt Seifried 2012-09-08 21:05:53 UTC
A MySQL bug entry is available for this issue:

http://bugs.mysql.com/bug.php?id=66550

Comment 12 Stefan Cornelius 2012-09-11 13:36:13 UTC
Public via http://www.openwall.com/lists/oss-security/2012/09/11/4

Comment 16 Stefan Cornelius 2012-10-05 06:09:33 UTC
Created mysql tracking bugs for this issue

Affects: fedora-all [bug 863320]

Comment 18 Tomas Hoger 2013-01-16 15:40:08 UTC
Following blog post suggests that the fix for this issue is included in upstream MySQL 5.5.29, but it does not completely and correctly resolve the issue:

http://www.mysqlperformanceblog.com/2013/01/13/cve-2012-4414-in-mysql-5-5-29-and-percona-server-5-5-29/


Note You need to log in before you can comment on or make changes to this bug.