SuSE 11.2 Security Update : MySQL (SAT Patch Number 7251)

medium Nessus Plugin ID 64531

Synopsis

The remote SuSE 11 host is missing one or more security updates.

Description

A stack-based buffer overflow in MySQL has been fixed that could have caused a Denial of Service or potentially allowed the execution of arbitrary code. (CVE-2012-5611)

Solution

Apply SAT patch number 7251.

See Also

https://bugzilla.novell.com/show_bug.cgi?id=792444

http://support.novell.com/security/cve/CVE-2012-5611.html

http://support.novell.com/security/cve/CVE-2012-5612.html

http://support.novell.com/security/cve/CVE-2012-5613.html

http://support.novell.com/security/cve/CVE-2012-5615.html

Plugin Details

Severity: Medium

ID: 64531

File Name: suse_11_libmysqlclient-devel-121227.nasl

Version: 1.5

Type: local

Agent: unix

Published: 2/10/2013

Updated: 1/19/2021

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.0

CVSS v2

Risk Factor: Medium

Base Score: 6.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:novell:suse_linux:11:libmysqlclient15-32bit, p-cpe:/a:novell:suse_linux:11:mysql-client, p-cpe:/a:novell:suse_linux:11:libmysqlclient_r15, cpe:/o:novell:suse_linux:11, p-cpe:/a:novell:suse_linux:11:libmysqlclient15, p-cpe:/a:novell:suse_linux:11:mysql-max, p-cpe:/a:novell:suse_linux:11:mysql-tools, p-cpe:/a:novell:suse_linux:11:libmysqlclient_r15-32bit, p-cpe:/a:novell:suse_linux:11:mysql

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 12/27/2012

Exploitable With

Metasploit (Oracle MySQL for Microsoft Windows FILE Privilege Abuse)

Reference Information

CVE: CVE-2012-5611, CVE-2012-5612, CVE-2012-5613, CVE-2012-5615