CVE Database
/

CVE-2012-2122

Back to search

CVE-2012-2122

Published: Jun 26, 2012

Modified: Aug 6, 2024

PUBLISHED

Description

sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x before 5.1.62, 5.2.x before 5.2.12, 5.3.x before 5.3.6, and 5.5.x before 5.5.23, when running in certain environments with certain implementations of the memcmp function, allows remote attackers to bypass authentication by repeatedly authenticating with the same incorrect password, which eventually causes a token comparison to succeed due to an improperly-checked return value.

VendorProductVersions

n/a

n/a

affected
n/a

References

53911
vdb-entry
x_refsource_BID
19092
exploit
x_refsource_EXPLOIT-DB
53372
third-party-advisory
x_refsource_SECUNIA
GLSA-201308-06
vendor-advisory
x_refsource_GENTOO
SUSE-SU-2012:0984
vendor-advisory
x_refsource_SUSE
1027143
vdb-entry
x_refsource_SECTRACK
49417
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now