CVE-2012-5614

Oracle MySQL 5.1.67 and earlier and 5.5.29 and earlier, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a denial of service (mysqld crash) via a SELECT command with an UpdateXML command containing XML with a large number of unique, nested elements.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:oracle:mysql:5.5.19:*:*:*:*:*:*:*
cpe:2.3:a:mariadb:mariadb:5.5.28a:*:*:*:*:*:*:*

Information

Published : 2012-12-03 12:49

Updated : 2014-02-21 04:55


NVD link : CVE-2012-5614

Mitre link : CVE-2012-5614


JSON object : View

Products Affected

mariadb

  • mariadb

oracle

  • mysql
CWE
CWE-20

Improper Input Validation