CVE-2012-2122
60Vexday Risk Score
Corrige pronto. Ella tiene exploit funcional público.
ssvc Attendepss 96%
de la publicación al arma0 días
Publicada en NVD26 jun
1ª PoC12 jun
metasploit9 jun
probabilidad de explotación
96%top 1% de las CVE
explotación observada
noninguna fuente lo reporta
7 exploit(s) público(s)
sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x before 5.1.62, 5.2.x before 5.2.12, 5.3.x before 5.3.6, and 5.5.x before 5.5.23, when running in certain environments with certain implementations of the memcmp function, allows remote attackers to bypass authentication by repeatedly authenticating with the same incorrect password, which eventually causes a token comparison to succeed due to an improperly-checked return value.
Productos afectados
n/a · n/aPoCs públicas encontradas — 7✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/19092githubgithub.com/Avinza/CVE-2012-2122-scanner★ 1githubgithub.com/cyberharsh/Oracle-mysql-CVE-2012-2122★ 1githubgithub.com/zhangkaibin0921/CVE-2012-2122★ 0githubgithub.com/netw0rk7/CVE-2012-2122-Home-Lab★ 0githubgithub.com/K3ysTr0K3R/CVE-2012-2122★ 0cve_referencewww.exploit-db.com/exploits/19092no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
Referencias
http://bugs.mysql.com/bug.php?id=64884http://kb.askmonty.org/en/mariadb-5162-release-notes/http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00007.htmlhttps://community.rapid7.com/community/metasploit/blog/2012/06/11/cve-2012-2122-a-tragically-comedic-security-flaw-in-mysqlhttp://seclists.org/oss-sec/2012/q2/493http://secunia.com/advisories/49417http://secunia.com/advisories/53372http://security.gentoo.org/glsa/glsa-201308-06.xmlhttp://securitytracker.com/id?1027143http://www.exploit-db.com/exploits/19092http://www.securityfocus.com/bid/53911