Latest Updates

Tuesday, 4 December 2012

Multiple MySQL database Zero-day vulnerabilities published


Practical Guide to Database Security & Compliance. Free Copy!
www.mcafee.com

Researcher discovered Multiple Zero-day vulnerabilities in MySQL database software including Stack based buffer overrun, Heap Based Overrun, Privilege Elevation, Denial of Service and  Remote Preauth User Enumeration.

Common Vulnerabilities and Exposures (CVE) assigned as :
CVE-2012-5611 — MySQL (Linux) Stack based buffer overrun PoC Zeroday
CVE-2012-5612 — MySQL (Linux) Heap Based Overrun PoC Zeroday
CVE-2012-5613 — MySQL (Linux) Database Privilege Elevation Zeroday Exploit
CVE-2012-5614 — MySQL Denial of Service Zeroday PoC
CVE-2012-5615 — MySQL Remote Preauth User Enumeration Zeroday

Multiple+MySQL+database+Zero-day+Vulnerabilities+published

Currently, all reported bugs are under review and most of the researchers believed that some of these can be duplicate of an existing bugs.

CVE-2012-5612 and CVE-2012-5614 could cause the SQL instance to crash, according to researchers. Where as another interesting bug CVE-2012-5615 allow attacker to find out that either any username exist on the Mysql server or not by reply- "Access denied".

Eric Posted MySQL Database Privilege Elevation 0day Exploit Demo:

Read more at http://thehackernews.com/2012/12/multiple-mysql-database-zero-day.html#wGpl1vyx2duwvwwp.99 
  • Blogger Comments
  • Facebook Comments

0 comments:

Post a Comment

Item Reviewed: Multiple MySQL database Zero-day vulnerabilities published Description: Rating: 5 Reviewed By: Ajay Devgan
Scroll to Top