CVE-2012-5627: MariaDB

Medium severity, CVSS 4.0. EPSS: 11.4% chance of exploitation in the next 30 days.

Oracle MySQL and MariaDB 5.5.x before 5.5.29, 5.3.x before 5.3.12, and 5.2.x before 5.2.14 does not modify the salt during multiple executions of the change_user command within the same connection which makes it easier for remote authenticated users to conduct brute force password guessing attacks.

Affected products

  • MariaDB MariaDB: from 5.2.0, before 5.2.14 (fixed in 5.2.14); from 5.3.0, before 5.3.12 (fixed in 5.3.12); from 5.5.0, before 5.5.29 (fixed in 5.5.29); version 10.0.0 only
  • Oracle MySQL: from 5.5.0, before 5.5.29 (fixed in 5.5.29)

Published 2013-10-01. Last modified 2026-06-16.