First published: Wed Sep 26 2012(Updated: )
It was found that the fix for <a href="https://access.redhat.com/security/cve/CVE-2009-4030">CVE-2009-4030</a> was removed from the MySQL packages as provided with RHSA-2012:0127 when it was updated to version 5.0.95. Upstream claimed to have corrected this in version 5.0.88, so the patch was removed when it did not apply. As a result, MySQL version 5.0.95-1.el5_7.1 became vulnerable to <a href="https://access.redhat.com/security/cve/CVE-2009-4030">CVE-2009-4030</a> again. For most default or typical configurations, this flaw has no impact. Please see <a class="bz_bug_link bz_status_CLOSED bz_closed bz_public " title="CLOSED ERRATA - CVE-2009-4030 mysql: Incomplete fix for CVE-2008-2079 / CVE-2008-4098" href="show_bug.cgi?id=543653#c4">https://bugzilla.redhat.com/show_bug.cgi?id=543653#c4</a> for further discussion on the possible scenarios where this flaw can be triggered. If the basedir and datadir directives are unchanged in MySQL's configuration or command-line arguments, this flaw has no impact.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
MySQL | <=5.0.88 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4452 is considered a moderate severity vulnerability.
To fix CVE-2012-4452, upgrade MySQL to a version higher than 5.0.88.
CVE-2012-4452 affects MySQL versions up to and including 5.0.88.
No specific patch is available for CVE-2012-4452, but upgrading the software resolves the issue.
CVE-2012-4452 addresses the removal of critical security fixes from MySQL packages.