Unrated severityNVD Advisory· Published Oct 1, 2013· Updated Apr 29, 2026
CVE-2012-5627
CVE-2012-5627
Description
Oracle MySQL and MariaDB 5.5.x before 5.5.29, 5.3.x before 5.3.12, and 5.2.x before 5.2.14 does not modify the salt during multiple executions of the change_user command within the same connection which makes it easier for remote authenticated users to conduct brute force password guessing attacks.
Affected products
3Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- security.gentoo.org/glsa/glsa-201308-06.xmlnvdPatchThird Party AdvisoryVDB Entry
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatchThird Party Advisory
- seclists.org/fulldisclosure/2012/Dec/58nvdExploitMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2012/Dec/83nvdExploitMailing ListThird Party Advisory
- seclists.org/oss-sec/2012/q4/424nvdMailing ListThird Party Advisory
- mariadb.atlassian.net/browse/MDEV-3915nvdBroken LinkVendor Advisory
- secunia.com/advisories/53372nvdNot Applicable
- www.mandriva.com/security/advisoriesnvdBroken Link
News mentions
0No linked articles in our index yet.