CVE-2012-5614: MariaDB
Medium severity, CVSS 4.0. EPSS: 13.2% chance of exploitation in the next 30 days.
Oracle MySQL 5.1.67 and earlier and 5.5.29 and earlier, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a denial of service (mysqld crash) via a SELECT command with an UpdateXML command containing XML with a large number of unique, nested elements.
Affected products
- MariaDB MariaDB: from 5.5.0, before 5.5.30 (fixed in 5.5.30); from 10.0.0, before 10.0.2 (fixed in 10.0.2)
- Oracle MySQL: from 5.1.0, up to and including 5.1.67; from 5.5.0, up to and including 5.5.29
- Red Hat Enterprise Linux Desktop: version 6.0 only
- Red Hat Enterprise Linux Eus: version 6.4 only
- Red Hat Enterprise Linux Server: version 6.0 only
- Red Hat Enterprise Linux Server Aus: version 6.4 only
- Red Hat Enterprise Linux Workstation: version 6.0 only
Published 2012-12-03. Last modified 2026-06-16.