CVE-2012-3160: Low severity mysql vulnerability
Published Oct 16, 2012
·Updated
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.65 and earlier, and 5.5.27 and earlier, allows local users to affect confidentiality via unknown vectors related to Server Installation.
Affected Software
14 affected components
Oracle MySQL>=5.1.0<=5.1.65
Oracle MySQL>=5.5.0<=5.5.27
Canonical Ubuntu Linux=10.04
Canonical Ubuntu Linux=11.10
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=12.10
Debian Debian Linux=6.0
Debian Debian Linux=7.0
MariaDB MariaDB>=5.1.0<5.1.66
MariaDB MariaDB>=5.5.0<5.5.28
redhat Enterprise Linux Desktop=6.0
redhat Enterprise Linux Eus=6.3
redhat Enterprise Linux Server=6.0
redhat Enterprise Linux Workstation=6.0
Remediation
Event History
Oct 16, 2012
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-3160?
CVE-2012-3160 has a variable severity rating, largely dependent on the deployment context.
2
How do I fix CVE-2012-3160?
To remediate CVE-2012-3160, upgrade MySQL Server to version 5.1.66 or later, or 5.5.28 or later.
3
What versions of MySQL are affected by CVE-2012-3160?
CVE-2012-3160 affects MySQL versions 5.1.65 and earlier, and 5.5.27 and earlier.
4
Can CVE-2012-3160 be exploited remotely?
CVE-2012-3160 primarily allows local users to affect confidentiality rather than being exploited remotely.
5
Are other database systems affected by CVE-2012-3160?
The CVE-2012-3160 vulnerability specifically pertains to Oracle MySQL and is not reported for other database systems.