Blog | G5 Cyber Security

Multiple MySQL database Zero-day vulnerabilities published

Vulnerabilities and Exposures (CVE) assigned as: “MySQL (Linux) Stack based buffer overrun, Heap Based Overrun, Privilege Elevation, Denial of Service and Remote Preauth User Enumeration. Currently, all reported bugs are under review and most of the researchers believed that some of these can be duplicate of an existing bugs. The bugs could cause the SQL instance to crash, according to researchers. Another interesting bug CVE-2012-5615 allow attacker to find out that either any username exist on the Mysql server or not by reply- “Access denied”.

Source: https://thehackernews.com/2012/12/multiple-mysql-database-zero-day.html

Exit mobile version