CVE-2012-5611

Exp

Stack-based buffer overflow in the acl_get function in Oracle MySQL 5.5.19 and other versions through 5.5.28, and 5.1.53 and other versions through 5.1.66, and MariaDB 5.5.2.x before 5.5.28a, 5.3.x before 5.3.11, 5.2.x before 5.2.13 and 5.1.x before 5.1.66, allows remote authenticated users to execute arbitrary code via a long argument to the GRANT FILE command.

Published: 2012-12-03 Last update: 2026-04-29 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2012-5611 is rated High Exploit Risk (70.2/100): CVSS Medium severity, with high exploitation likelihood (EPSS 24.56%, 98th percentile). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2012-5611

EDB-ID Source Kind Published Link
23075 exploit_db edb 2012-12-02 Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2012-5611

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 66.65% 24.56% -42.08%
2 2025-12-28 62.44% 66.65% +4.21%
3 2025-12-27 62.44%

Full EPSS history (28 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2012-5611

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
6.5 2.0 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:S)
A single authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:P)
Partial availability impact.
8.0 6.4 [email protected]

Weakness enumeration for CVE-2012-5611

OS Trackers for CVE-2012-5611

vendor priority summary link
gentoo high CVE-2012-5611: 1 GLSA(s) (201308-06), 1 atom(s) (dev-db/mysql); latest impact high. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2012-5611
redhat high https://access.redhat.com/security/cve/CVE-2012-5611
suse medium CVE-2012-5611 severity moderate: SUSE including 92 source package names (liblz4-1-1.8.0-3.5.2, libmariadb-devel-3.1.22-2.35.1, …), 185 product×package rows across 22 product lines (SUSE CaaS Platform 4.0, SUSE Linux Enterprise Desktop 11 SP2, … (22 product lines)): Fixed 185. https://www.suse.com/security/cve/CVE-2012-5611/
ubuntu medium CVE-2012-5611 medium priority: Ubuntu including 3 source packages (mysql-5.1, mysql-5.5, mysql-dfsg-5.1), 18 status rows across 6 suites (hardy, lucid, oneiric, precise, quantal, upstream): DNE 11, released 4, needs-triage 3. https://ubuntu.com/security/CVE-2012-5611

NVD evaluator notes for CVE-2012-5611

Comment: per http://www.openwall.com/lists/oss-security/2012/12/02/3, this vulnerability is only on linux-based software installations

Affected software / configurations for CVE-2012-5611

Vendor Product Version Raw CPE
mariadb mariadb 5.1.41 cpe:2.3:a:mariadb:mariadb:5.1.41:*:*:*:*:*:*:*
mariadb mariadb 5.1.42 cpe:2.3:a:mariadb:mariadb:5.1.42:*:*:*:*:*:*:*
mariadb mariadb 5.1.44 cpe:2.3:a:mariadb:mariadb:5.1.44:*:*:*:*:*:*:*
mariadb mariadb 5.1.47 cpe:2.3:a:mariadb:mariadb:5.1.47:*:*:*:*:*:*:*
mariadb mariadb 5.1.49 cpe:2.3:a:mariadb:mariadb:5.1.49:*:*:*:*:*:*:*
mariadb mariadb 5.1.50 cpe:2.3:a:mariadb:mariadb:5.1.50:*:*:*:*:*:*:*
mariadb mariadb 5.1.51 cpe:2.3:a:mariadb:mariadb:5.1.51:*:*:*:*:*:*:*
mariadb mariadb 5.1.53 cpe:2.3:a:mariadb:mariadb:5.1.53:*:*:*:*:*:*:*
mariadb mariadb 5.1.55 cpe:2.3:a:mariadb:mariadb:5.1.55:*:*:*:*:*:*:*
mariadb mariadb 5.1.60 cpe:2.3:a:mariadb:mariadb:5.1.60:*:*:*:*:*:*:*
mariadb mariadb 5.1.61 cpe:2.3:a:mariadb:mariadb:5.1.61:*:*:*:*:*:*:*
mariadb mariadb 5.1.62 cpe:2.3:a:mariadb:mariadb:5.1.62:*:*:*:*:*:*:*
mariadb mariadb 5.2.0 cpe:2.3:a:mariadb:mariadb:5.2.0:*:*:*:*:*:*:*
mariadb mariadb 5.2.1 cpe:2.3:a:mariadb:mariadb:5.2.1:*:*:*:*:*:*:*
mariadb mariadb 5.2.2 cpe:2.3:a:mariadb:mariadb:5.2.2:*:*:*:*:*:*:*
mariadb mariadb 5.2.3 cpe:2.3:a:mariadb:mariadb:5.2.3:*:*:*:*:*:*:*
mariadb mariadb 5.2.4 cpe:2.3:a:mariadb:mariadb:5.2.4:*:*:*:*:*:*:*
mariadb mariadb 5.2.5 cpe:2.3:a:mariadb:mariadb:5.2.5:*:*:*:*:*:*:*
mariadb mariadb 5.2.6 cpe:2.3:a:mariadb:mariadb:5.2.6:*:*:*:*:*:*:*
mariadb mariadb 5.2.7 cpe:2.3:a:mariadb:mariadb:5.2.7:*:*:*:*:*:*:*
mariadb mariadb 5.2.8 cpe:2.3:a:mariadb:mariadb:5.2.8:*:*:*:*:*:*:*
mariadb mariadb 5.2.9 cpe:2.3:a:mariadb:mariadb:5.2.9:*:*:*:*:*:*:*
mariadb mariadb 5.2.10 cpe:2.3:a:mariadb:mariadb:5.2.10:*:*:*:*:*:*:*
mariadb mariadb 5.2.11 cpe:2.3:a:mariadb:mariadb:5.2.11:*:*:*:*:*:*:*
mariadb mariadb 5.2.12 cpe:2.3:a:mariadb:mariadb:5.2.12:*:*:*:*:*:*:*
mariadb mariadb 5.3.0 cpe:2.3:a:mariadb:mariadb:5.3.0:*:*:*:*:*:*:*
mariadb mariadb 5.3.1 cpe:2.3:a:mariadb:mariadb:5.3.1:*:*:*:*:*:*:*
mariadb mariadb 5.3.2 cpe:2.3:a:mariadb:mariadb:5.3.2:*:*:*:*:*:*:*
mariadb mariadb 5.3.3 cpe:2.3:a:mariadb:mariadb:5.3.3:*:*:*:*:*:*:*
mariadb mariadb 5.3.4 cpe:2.3:a:mariadb:mariadb:5.3.4:*:*:*:*:*:*:*
mariadb mariadb 5.3.5 cpe:2.3:a:mariadb:mariadb:5.3.5:*:*:*:*:*:*:*
mariadb mariadb 5.3.6 cpe:2.3:a:mariadb:mariadb:5.3.6:*:*:*:*:*:*:*
mariadb mariadb 5.3.7 cpe:2.3:a:mariadb:mariadb:5.3.7:*:*:*:*:*:*:*
mariadb mariadb 5.3.8 cpe:2.3:a:mariadb:mariadb:5.3.8:*:*:*:*:*:*:*
mariadb mariadb 5.3.9 cpe:2.3:a:mariadb:mariadb:5.3.9:*:*:*:*:*:*:*
mariadb mariadb 5.3.10 cpe:2.3:a:mariadb:mariadb:5.3.10:*:*:*:*:*:*:*
mariadb mariadb 5.5.20 cpe:2.3:a:mariadb:mariadb:5.5.20:*:*:*:*:*:*:*
mariadb mariadb 5.5.21 cpe:2.3:a:mariadb:mariadb:5.5.21:*:*:*:*:*:*:*
mariadb mariadb 5.5.22 cpe:2.3:a:mariadb:mariadb:5.5.22:*:*:*:*:*:*:*
mariadb mariadb 5.5.23 cpe:2.3:a:mariadb:mariadb:5.5.23:*:*:*:*:*:*:*
mariadb mariadb 5.5.24 cpe:2.3:a:mariadb:mariadb:5.5.24:*:*:*:*:*:*:*
mariadb mariadb 5.5.25 cpe:2.3:a:mariadb:mariadb:5.5.25:*:*:*:*:*:*:*
mariadb mariadb 5.5.27 cpe:2.3:a:mariadb:mariadb:5.5.27:*:*:*:*:*:*:*
mariadb mariadb 5.5.28 cpe:2.3:a:mariadb:mariadb:5.5.28:*:*:*:*:*:*:*
oracle mysql 5.1.53 cpe:2.3:a:oracle:mysql:5.1.53:*:*:*:*:*:*:*
oracle mysql 5.5.19 cpe:2.3:a:oracle:mysql:5.5.19:*:*:*:*:*:*:*

References for CVE-2012-5611

URL Tags
http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00000.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00001.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00002.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00013.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-01/msg00020.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00000.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-updates/2013-09/msg00010.html Mailing List Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2012-1551.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-0180.html Third Party Advisory
http://seclists.org/fulldisclosure/2012/Dec/4 Mailing List Third Party Advisory
http://secunia.com/advisories/51443 Broken Link
http://secunia.com/advisories/53372 Broken Link
http://security.gentoo.org/glsa/glsa-201308-06.xml Third Party Advisory
http://www.debian.org/security/2012/dsa-2581 Third Party Advisory
http://www.exploit-db.com/exploits/23075 Third Party Advisory VDB Entry
http://www.mandriva.com/security/advisories?name=MDVSA-2013:102 Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2013:150 Third Party Advisory
http://www.openwall.com/lists/oss-security/2012/12/02/3 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2012/12/02/4 Mailing List Third Party Advisory
http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html Third Party Advisory
http://www.ubuntu.com/usn/USN-1658-1 Third Party Advisory
http://www.ubuntu.com/usn/USN-1703-1 Third Party Advisory
https://kb.askmonty.org/en/mariadb-5166-release-notes/ Third Party Advisory
https://kb.askmonty.org/en/mariadb-5213-release-notes/ Third Party Advisory
https://kb.askmonty.org/en/mariadb-5311-release-notes/ Third Party Advisory
https://kb.askmonty.org/en/mariadb-5528a-release-notes/ Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16395 Third Party Advisory
cvelogic Threat Intelligence