← volver
CVE-2012-2122

CVE-2012-2122

60Vexday Risk Score

Corrige pronto. Ella tiene exploit funcional público.

ssvc Attendepss 97%
de la publicación al arma0 días
Publicada en NVD26 jun
1ª PoC12 jun
metasploit9 jun
probabilidad de explotación
97%top 1% de las CVE
explotación observada
noninguna fuente lo reporta
7 exploit(s) público(s)
Lo que declaran los fabricantes (VEX)

Declaraciones oficiales de los fabricantes en formato CSAF/VEX: si su producto está afectado, ya corregido o descartado — y por qué. Es afirmación del fabricante, no juicio de Vexday.

Afectado
1 producto
Red Hat Enterprise Linux 5
none_available: Affected
Corregido
8 productos (116 componentes)
Red Hat Enterprise Linux Server (v. 6) · Red Hat Enterprise Linux Server Optional (v. 6) · Red Hat Enterprise Linux Workstation (v. 6) · Red Hat Enterprise Linux Desktop Optional (v. 6) · Red Hat Enterprise Linux HPC Node Optional (v. 6) · y otros 3
sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x before 5.1.62, 5.2.x before 5.2.12, 5.3.x before 5.3.6, and 5.5.x before 5.5.23, when running in certain environments with certain implementations of the memcmp function, allows remote attackers to bypass authentication by repeatedly authenticating with the same incorrect password, which eventually causes a token comparison to succeed due to an improperly-checked return value.
Productos afectados
n/a · n/a
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.