Vulnerability Description
MariaDB 5.5.x before 5.5.30, 5.3.x before 5.3.13, 5.2.x before 5.2.15, and 5.1.x before 5.1.68, and Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote attackers to cause a denial of service (crash) via a crafted geometry feature that specifies a large number of points, which is not properly handled when processing the binary representation of this feature, related to a numeric calculation error.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mariadb | Mariadb | >= 5.5.0, < 5.5.32 |
| Oracle | Mysql | >= 5.1.0, <= 5.1.69 |
| Redhat | Enterprise Linux | 5 |
| Debian | Debian Linux | 7.0 |
| Canonical | Ubuntu Linux | 10.04 |
| Opensuse | Opensuse | 11.4 |
| Suse | Linux Enterprise Desktop | 11 |
| Suse | Linux Enterprise Server | 11 |
| Suse | Linux Enterprise Software Development Kit | 11 |
Related Weaknesses (CWE)
References
- http://lists.askmonty.org/pipermail/commits/2013-March/004371.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00022.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2013-10/msg00001.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00024.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-09/msg00008.htmlMailing ListThird Party Advisory
- http://seclists.org/oss-sec/2013/q1/671Mailing ListThird Party Advisory
- http://secunia.com/advisories/52639Not Applicable
- http://secunia.com/advisories/54300Not Applicable
- http://security.gentoo.org/glsa/glsa-201409-04.xmlThird Party Advisory
- http://www.debian.org/security/2013/dsa-2818Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.htmlThird Party Advisory
- http://www.osvdb.org/91415Broken Link
- http://www.securityfocus.com/bid/58511ExploitThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-1909-1Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=919247Issue TrackingThird Party Advisory
FAQ
What is CVE-2013-1861?
CVE-2013-1861 is a vulnerability with a CVSS score of 5.0 (MEDIUM). MariaDB 5.5.x before 5.5.30, 5.3.x before 5.3.13, 5.2.x before 5.2.15, and 5.1.x before 5.1.68, and Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote attackers ...
How severe is CVE-2013-1861?
CVE-2013-1861 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-1861?
Check the references section above for vendor advisories and patch information. Affected products include: Mariadb Mariadb, Oracle Mysql, Redhat Enterprise Linux, Debian Debian Linux, Canonical Ubuntu Linux.