First published: Thu Jan 17 2013(Updated: )
Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier and 5.5.28 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
MySQL | >=5.1.0<=5.1.66 | |
MySQL | >=5.5.0<=5.5.28 | |
MariaDB | >=5.1.0<5.1.67 | |
MariaDB | >=5.2.0<5.2.14 | |
MariaDB | >=5.3.0<5.3.12 | |
MariaDB | >=5.5.0<5.5.29 | |
MariaDB | =10.0.0 | |
Ubuntu | =10.04 | |
Ubuntu | =11.10 | |
Ubuntu | =12.04 | |
Ubuntu | =12.10 | |
Red Hat Enterprise Linux Desktop | =6.0 | |
Red Hat Enterprise Linux Server EUS | =6.3 | |
Red Hat Enterprise Linux Server | =6.0 | |
Red Hat Enterprise Linux Workstation | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-1705 is classified as a vulnerability that affects availability due to unspecified issues in the Oracle MySQL Server component.
To mitigate CVE-2012-1705, you should upgrade to MySQL versions 5.1.67 and later or 5.5.29 and later.
CVE-2012-1705 affects MySQL versions 5.1.66 and earlier as well as 5.5.28 and earlier.
Yes, CVE-2012-1705 can be exploited by remote authenticated users to affect the availability of the database.
If unable to upgrade, consider implementing strict access controls and monitoring to reduce the risk of exploitation associated with CVE-2012-1705.