peter bassill · operator
$ cve CVE-2013-1861 JSON

CVE-2013-1861 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 18.7% (pctl 97)

Patch early

A public exploit exists.

Description

MariaDB 5.5.x before 5.5.30, 5.3.x before 5.3.13, 5.2.x before 5.2.15, and 5.1.x before 5.1.68, and Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote attackers to cause a denial of service (crash) via a crafted geometry feature that specifies a large number of points, which is not properly handled when processing the binary representation of this feature, related to a numeric calculation error.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS18.68% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2013-03-28
Last modified2026-06-16

Affected (9)

VendorProduct
canonicalubuntu linux
debiandebian linux
mariadbmariadb
opensuseopensuse
oraclemysql
redhatenterprise linux
suselinux enterprise desktop
suselinux enterprise server
suselinux enterprise software development kit

Public exploits

SourceTitleDate
exploit-dbMySQL / MariaDB - Geometry Query Denial of Service2013-03-07

References

→ the Explorer  ·  watch your stack  ·  NVD