CVE-2012-5614: MariaDB

Medium severity, CVSS 4.0. EPSS: 13.2% chance of exploitation in the next 30 days.

Oracle MySQL 5.1.67 and earlier and 5.5.29 and earlier, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a denial of service (mysqld crash) via a SELECT command with an UpdateXML command containing XML with a large number of unique, nested elements.

Affected products

  • MariaDB MariaDB: from 5.5.0, before 5.5.30 (fixed in 5.5.30); from 10.0.0, before 10.0.2 (fixed in 10.0.2)
  • Oracle MySQL: from 5.1.0, up to and including 5.1.67; from 5.5.0, up to and including 5.5.29
  • Red Hat Enterprise Linux Desktop: version 6.0 only
  • Red Hat Enterprise Linux Eus: version 6.4 only
  • Red Hat Enterprise Linux Server: version 6.0 only
  • Red Hat Enterprise Linux Server Aus: version 6.4 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only

Published 2012-12-03. Last modified 2026-06-16.