Multiple SQL injection vulnerabilities in the replication code in Oracle MySQL possibly before 5.5.29, and MariaDB 5.1.x through 5.1.62, 5.2.x through 5.2.12, 5.3.x through 5.3.7, and 5.5.x through 5.5.25, allow remote authenticated users to execute arbitrary SQL commands via vectors related to the binary log. NOTE: as of 20130116, Oracle has not commented on claims from a downstream vendor that the fix in MySQL 5.5.29 is incomplete.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2013-01-22T23:00:00
Updated: 2024-08-06T20:35:09.480Z
Reserved: 2012-08-21T00:00:00
Link: CVE-2012-4414
Vulnrichment
No data.
NVD
Status : Modified
Published: 2013-01-22T23:55:02.650
Modified: 2024-11-21T01:42:50.050
Link: CVE-2012-4414
Redhat