← back
CVE-2012-2122

CVE-2012-2122

60Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 96%
from disclosure to weapon0 days
Published on NVDJun 26
1st PoCJun 12
metasploitJun 9
exploitation probability
96%top 1% of all CVEs
observed exploitation
nono source reports it
7 public exploit(s)
sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x before 5.1.62, 5.2.x before 5.2.12, 5.3.x before 5.3.6, and 5.5.x before 5.5.23, when running in certain environments with certain implementations of the memcmp function, allows remote attackers to bypass authentication by repeatedly authenticating with the same incorrect password, which eventually causes a token comparison to succeed due to an improperly-checked return value.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.