CVE-2013-1861 is a denial-of-service vulnerability affecting MariaDB and Oracle MySQL database servers, specifically versions 5.5.x, 5.3.x, 5.2.x, and 5.1.x, as well as various distributions like Canonical, Debian, and Red Hat. Remote attackers can crash the database by sending a crafted geometry feature with an excessive number of points, leading to a numeric calculation error during binary processing. With a CVSS score of 5.0, this vulnerability is of medium severity, requiring no authentication and having low attack complexity, but only resulting in a denial of service. While there is an ExploitDB entry for a denial-of-service exploit, there is no evidence of active exploitation, Metasploit modules, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.5.0, < 5.5.32CPE matchmatch criteria | cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:* | ||
>= 10.0.0, < 10.0.4CPE matchmatch criteria | cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:* | ||
>= 5.1.0, <= 5.1.69CPE matchmatch criteria | cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:* | ||
>= 5.5.0, <= 5.5.31CPE matchmatch criteria | cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:* | ||
>= 5.6.0, <= 5.6.11CPE matchmatch criteria | cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.