Vulnerability CVE-2013-1861


Published: 2013-03-28   Modified: 2013-03-29

Description:
MariaDB 5.5.x before 5.5.30, 5.3.x before 5.3.13, 5.2.x before 5.2.15, and 5.1.x before 5.1.68, and Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote attackers to cause a denial of service (crash) via a crafted geometry feature that specifies a large number of points, which is not properly handled when processing the binary representation of this feature, related to a numeric calculation error.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
MySQL/MariaDB geometry query crashes mysqld
Kurt Seifried
15.03.2013

Type:

CWE-119

(Improper Restriction of Operations within the Bounds of a Memory Buffer)

CVSS2 => (AV:N/AC:L/Au:N/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial
Affected software
Redhat -> Enterprise linux 
Mariadb -> Mariadb 

 References:
http://lists.askmonty.org/pipermail/commits/2013-March/004371.html
http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00022.html
http://lists.opensuse.org/opensuse-security-announce/2013-10/msg00001.html
http://lists.opensuse.org/opensuse-updates/2013-08/msg00024.html
http://lists.opensuse.org/opensuse-updates/2013-09/msg00008.html
http://seclists.org/oss-sec/2013/q1/671
http://security.gentoo.org/glsa/glsa-201409-04.xml
http://www.debian.org/security/2013/dsa-2818
http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html
http://www.securityfocus.com/bid/58511
http://www.ubuntu.com/usn/USN-1909-1
https://bugzilla.redhat.com/show_bug.cgi?id=919247
https://exchange.xforce.ibmcloud.com/vulnerabilities/82895
https://mariadb.atlassian.net/browse/MDEV-4252

Copyright 2024, cxsecurity.com

 

Back to Top