CVE Vulnerabilities

CVE-2012-5627

Insufficiently Protected Credentials

Published: Oct 01, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
2.6 LOW
AV:N/AC:H/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Oracle MySQL and MariaDB 5.5.x before 5.5.29, 5.3.x before 5.3.12, and 5.2.x before 5.2.14 does not modify the salt during multiple executions of the change_user command within the same connection which makes it easier for remote authenticated users to conduct brute force password guessing attacks.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

NameVendorStart VersionEnd Version
MysqlOracle5.5.0 (including)5.5.29 (excluding)
Mariadb-5.5Ubuntuupstream*
Mysql-5.5Ubuntuesm-infra-legacy/trusty*
Mysql-5.5Ubuntuprecise*
Mysql-5.5Ubuntuquantal*
Mysql-5.5Ubunturaring*
Mysql-5.5Ubuntusaucy*
Mysql-5.5Ubuntutrusty*
Mysql-5.5Ubuntutrusty/esm*
Mysql-5.5Ubuntuutopic*
Mysql-5.6Ubuntutrusty*
Mysql-5.6Ubuntuutopic*
Mysql-5.6Ubuntuvivid*
Mysql-5.6Ubuntuwily*

Potential Mitigations

References