CVE-2013-1861: Canonical Ubuntu Linux

Medium severity, CVSS 5.0. EPSS: 18.7% chance of exploitation in the next 30 days.

MariaDB 5.5.x before 5.5.30, 5.3.x before 5.3.13, 5.2.x before 5.2.15, and 5.1.x before 5.1.68, and Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote attackers to cause a denial of service (crash) via a crafted geometry feature that specifies a large number of points, which is not properly handled when processing the binary representation of this feature, related to a numeric calculation error.

Affected products

  • Canonical Ubuntu Linux: version 10.04 only; version 12.04 only; version 12.10 only; version 13.04 only
  • Debian Debian Linux: version 7.0 only
  • MariaDB MariaDB: from 5.5.0, before 5.5.32 (fixed in 5.5.32); from 10.0.0, before 10.0.4 (fixed in 10.0.4)
  • Opensuse Opensuse: version 11.4 only; version 12.2 only; version 12.3 only
  • Oracle MySQL: from 5.1.0, up to and including 5.1.69; from 5.5.0, up to and including 5.5.31; from 5.6.0, up to and including 5.6.11
  • Red Hat Enterprise Linux: version 5 only; version 6.0 only
  • Suse Linux Enterprise Desktop: version 11 only
  • Suse Linux Enterprise Server: version 11 only
  • Suse Linux Enterprise Software Development Kit: version 11 only

Published 2013-03-28. Last modified 2026-06-16.