{"id":"CVE-2012-3167","description":"Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.63 and earlier, and 5.5.25 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Full Text Search.","cvssScore":3.5,"cvssVersion":"2.0","cvssVector":"AV:N/AC:M/Au:S/C:N/I:N/A:P","cvssMetrics":[{"version":"2.0","score":3.5,"vector":"AV:N/AC:M/Au:S/C:N/I:N/A:P","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"}],"resolved":"NOT-APPLICABLE","published":"2012-10-17","lastModified":"2026-06-16","affectedProducts":[{"vendor":"oracle","product":"mysql","versionStart":"\u003e=5.1.0","versionEnd":"\u003c=5.1.63"},{"vendor":"oracle","product":"mysql","versionStart":"\u003e=5.5.0","versionEnd":"\u003c=5.5.25"},{"vendor":"debian","product":"debian linux","version":"6.0"},{"vendor":"debian","product":"debian linux","version":"7.0"},{"vendor":"canonical","product":"ubuntu linux","version":"10.04"},{"vendor":"canonical","product":"ubuntu linux","version":"11.10"},{"vendor":"canonical","product":"ubuntu linux","version":"12.04"},{"vendor":"canonical","product":"ubuntu linux","version":"12.10"},{"vendor":"mariadb","product":"mariadb","versionStart":"\u003e=5.1.0","versionEnd":"\u003c5.1.66"},{"vendor":"mariadb","product":"mariadb","versionStart":"\u003e=5.5.0","versionEnd":"\u003c5.5.27"},{"vendor":"redhat","product":"enterprise linux desktop","version":"6.0"},{"vendor":"redhat","product":"enterprise linux eus","version":"6.3"},{"vendor":"redhat","product":"enterprise linux server","version":"6.0"},{"vendor":"redhat","product":"enterprise linux workstation","version":"6.0"}],"totalAffectedProducts":8,"references":[{"url":"http://rhn.redhat.com/errata/RHSA-2012-1462.html","source":"secalert_us@oracle.com","tags":["Third Party Advisory"]},{"url":"http://secunia.com/advisories/51177","source":"secalert_us@oracle.com","tags":["Not Applicable","Third Party Advisory"]},{"url":"http://secunia.com/advisories/51309","source":"secalert_us@oracle.com","tags":["Not Applicable","Third Party Advisory"]},{"url":"http://secunia.com/advisories/53372","source":"secalert_us@oracle.com","tags":["Not Applicable","Third Party Advisory"]},{"url":"http://security.gentoo.org/glsa/glsa-201308-06.xml","source":"secalert_us@oracle.com","tags":["Third Party Advisory"]},{"url":"http://www.debian.org/security/2012/dsa-2581","source":"secalert_us@oracle.com","tags":["Third Party Advisory"]},{"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2013:150","source":"secalert_us@oracle.com","tags":["Broken Link","Third Party Advisory"]},{"url":"http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html","source":"secalert_us@oracle.com","tags":["Patch","Vendor Advisory"]},{"url":"http://www.ubuntu.com/usn/USN-1621-1","source":"secalert_us@oracle.com","tags":["Third Party Advisory"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/79392","source":"secalert_us@oracle.com","tags":["Third Party Advisory","VDB Entry"]}],"reasoning":{"decidingSource":"h2-history","decidingReason":"Historical classification excluded this CVE and no tracked product appears on the record, so it is not a Java problem ARMR was ever asked to address.","verdicts":[{"rule":"rejected","stage":"identity","outcome":"no-match"},{"rule":"armr-patch-file","stage":"scope","outcome":"no-match"},{"rule":"armr-secure-rule-file","stage":"scope","outcome":"no-match"},{"rule":"manual-classification","stage":"scope","outcome":"no-match"},{"rule":"h2-history","stage":"scope","outcome":"matched","status":"NOT-APPLICABLE","detail":"Found in legacy manual classifications","decisive":true}]},"oracleAdvisories":[{"advisory":"Oracle Critical Patch Update October 2012","releaseType":"CPU","quarter":"2012-Q4","url":"https://www.oracle.com/security-alerts/cpuoct2012.html","products":[{"product":"Oracle MySQL","component":"Server Full Text Search","affectedVersions":"5.1.63 and earlier, 5.5.25 and earlier"}]}],"assessment":{"record":{"state":"active"},"protection":{"level":"none"},"action":{"state":"not-needed","type":"none"},"review":{"state":"human","basis":"manual-review"}},"h2Comments":"## Manual Classification Context\n\n\n**Labels:** MYSQL PROTOCOL, SERVER FULL TEXT SEARCH\n\n**Products:** MYSQL, MYSQL SERVER, ORACLE MYSQL","signals":{"hasPOC":false,"pocCount":0},"kev":{"inKEV":false},"epss":{"available":true,"score":0.02707,"percentile":0.85134},"ssvc":{"available":false}}