Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 446240 (CVE-2012-5627) - <dev-db/mariadb-{5.2.14,5.3.12,5.5.29} : insecure salt usage (CVE-2012-5627)
Summary: <dev-db/mariadb-{5.2.14,5.3.12,5.5.29} : insecure salt usage (CVE-2012-5627)
Status: RESOLVED FIXED
Alias: CVE-2012-5627
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: http://www.openwall.com/lists/oss-sec...
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2012-12-06 11:28 UTC by Agostino Sarubbo
Modified: 2013-10-06 23:07 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2012-12-06 11:28:07 UTC
From $URL :

Noticed another post by kingcope on full-disclosure, which basically
boils down to re-use of a salt-value when transmitting passwords
over a network.

If you could MITM/capture network packets, you could use this
weakness to determine the passwords.

References:
http://seclists.org/fulldisclosure/2012/Dec/58
https://bugzilla.redhat.com/show_bug.cgi?id=883719


New bug because bug 434874 has ebuild status and this should be upstream.
Comment 1 Brian Evans (RETIRED) gentoo-dev 2013-03-01 15:55:46 UTC
Upstream has released and fixed versions are in portage ( 5.5.29, 5.3.12, 5.2.14 )
Comment 2 Agostino Sarubbo gentoo-dev 2013-03-17 17:30:10 UTC
@mysql team:

the 5.1 series seems to be affected ( https://mariadb.atlassian.net/browse/MDEV-3915 ) but 5.1.67 does not contain a fix.

Please clean the vulnerable versions.
Comment 3 Agostino Sarubbo gentoo-dev 2013-08-29 15:43:50 UTC
As I said, the 5.1 series is not fixed. This version is now masked in the tree.

The rest of the cleanup is done. Closing as noglsa.
Comment 4 GLSAMaker/CVETool Bot gentoo-dev 2013-10-06 23:07:36 UTC
CVE-2012-5627 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5627):
  Oracle MySQL and MariaDB 5.5.x before 5.5.29, 5.3.x before 5.3.12, and 5.2.x
  before 5.2.14 does not modify the salt during multiple executions of the
  change_user command within the same connection which makes it easier for
  remote authenticated users to conduct brute force password guessing attacks.