CVE-2012-5615
Publication date 3 December 2012
Last updated 24 July 2024
Ubuntu priority
Oracle MySQL 5.5.38 and earlier, 5.6.19 and earlier, and MariaDB 5.5.28a, 5.3.11, 5.2.13, 5.1.66, and possibly other versions, generates different error messages with different time delays depending on whether a user name exists, which allows remote attackers to enumerate valid usernames.
Status
Package | Ubuntu Release | Status |
---|---|---|
mariadb-5.5 | ||
14.04 LTS trusty | Not in release | |
mysql-5.5 | ||
14.04 LTS trusty |
Fixed 5.5.40-0ubuntu0.14.04.1
|
|
mysql-5.6 | ||
14.04 LTS trusty |
Fixed 5.6.27-0ubuntu0.14.04.1
|
|
mysql-dfsg-5.1 | ||
14.04 LTS trusty | Not in release | |
Patch details
Package | Patch details |
---|---|
mysql-5.5 |
References
Related Ubuntu Security Notices (USN)
- USN-2384-1
- MySQL vulnerabilities
- 15 October 2014