VYPR
Unrated severityNVD Advisory· Published Oct 1, 2013· Updated Apr 29, 2026

CVE-2012-5627

CVE-2012-5627

Description

Oracle MySQL and MariaDB 5.5.x before 5.5.29, 5.3.x before 5.3.12, and 5.2.x before 5.2.14 does not modify the salt during multiple executions of the change_user command within the same connection which makes it easier for remote authenticated users to conduct brute force password guessing attacks.

Affected products

3
  • cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*
    Range: >=5.5.0,<5.5.29
  • MariaDB/MariaDB2 versions
    cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*range: >=5.2.0,<5.2.14
    • cpe:2.3:a:mariadb:mariadb:10.0.0:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

8

News mentions

0

No linked articles in our index yet.