CVE

Id
58870  
CVE No.
CVE-2012-5627  
Status
Candidate  
Description
Oracle MySQL and MariaDB 5.5.x before 5.5.29, 5.3.x before 5.3.12, and 5.2.x before 5.2.14 does not modify the salt during multiple executions of the change_user command within the same connection which makes it easier for remote authenticated users to conduct brute force password guessing attacks.  
Phase
Assigned (20121024)  
Votes
None (candidate not yet proposed)  
Comments