There are numerous places in the code where SQL statements are generated and written into the binary log. User-supplied identifiers (table names, field names, etc.) are not always properly quoted (for example, the proper quoted form of SPECI`AL is `SPECI``AL`), so authorized users that have privileges to modify a table (any non-temporary table) can inject arbitrary SQL into the binary log.
Such injected SQL will be executed by the slave or when a DBA does a mysqlbinlog|mysql style point-in-time recovery.
During the normal MySQL replication (master-slave, not mysqlbinlog|mysql), the options to exploit these vulnerabilities are somewhat limited by the fact, that the slave does not execute many statements, when it expects the one. So, one can not inject a new SQL statement. But one can extend the WHERE condition, or modify tables that he usually would have no access to.
Just to be clear: to exploit this one needs a valid account on the server and privileges to modify data.
To trigger the bug one can use, for example,
create temporary table temp(a int);
|
create table `a``b` (a int);
|
drop table `a``b`, temp;
|
show binlog events;
|
This issue was reported on MySQL bug tracker: http://bugs.mysql.com/66550
It has CVE identifier CVE-2012-4414
The patches are available on launchpad:
There are no comments yet on this issue.
{"report":{"fcp":1477.1000003814697,"ttfb":597.8000001907349,"pageVisibility":"visible","entityId":12406,"key":"jira.project.issue.view-issue","isInitial":true,"threshold":1000,"elementTimings":{},"userDeviceMemory":8,"userDeviceProcessors":64,"apdex":0.5,"journeyId":"be91a5c7-38d8-4f0d-b690-694b73f5ac9d","navigationType":0,"readyForUser":1549.6000003814697,"redirectCount":0,"resourceLoadedEnd":2248.5,"resourceLoadedStart":603.3000001907349,"resourceTiming":[{"duration":350.3999996185303,"initiatorType":"link","name":"https://jira.mariadb.org/s/2c21342762a6a02add1c328bed317ffd-CDN/lu2cib/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/css/_super/batch.css","startTime":603.3000001907349,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":603.3000001907349,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":953.6999998092651,"responseStart":0,"secureConnectionStart":0},{"duration":350.9000005722046,"initiatorType":"link","name":"https://jira.mariadb.org/s/7ebd35e77e471bc30ff0eba799ebc151-CDN/lu2cib/820016/12ta74/494e4c556ecbb29f90a3d3b4f09cb99c/_/download/contextbatch/css/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true&whisper-enabled=true","startTime":603.5,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":603.5,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":954.4000005722046,"responseStart":0,"secureConnectionStart":0},{"duration":409.30000019073486,"initiatorType":"script","name":"https://jira.mariadb.org/s/0917945aaa57108d00c5076fea35e069-CDN/lu2cib/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/js/_super/batch.js?locale=en","startTime":603.8000001907349,"connectEnd":603.8000001907349,"connectStart":603.8000001907349,"domainLookupEnd":603.8000001907349,"domainLookupStart":603.8000001907349,"fetchStart":603.8000001907349,"redirectEnd":0,"redirectStart":0,"requestStart":603.8000001907349,"responseEnd":1013.1000003814697,"responseStart":1013.1000003814697,"secureConnectionStart":603.8000001907349},{"duration":504.30000019073486,"initiatorType":"script","name":"https://jira.mariadb.org/s/2d8175ec2fa4c816e8023260bd8c1786-CDN/lu2cib/820016/12ta74/494e4c556ecbb29f90a3d3b4f09cb99c/_/download/contextbatch/js/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en&slack-enabled=true&whisper-enabled=true","startTime":604,"connectEnd":604,"connectStart":604,"domainLookupEnd":604,"domainLookupStart":604,"fetchStart":604,"redirectEnd":0,"redirectStart":0,"requestStart":604,"responseEnd":1108.3000001907349,"responseStart":1108.3000001907349,"secureConnectionStart":604},{"duration":508.30000019073486,"initiatorType":"script","name":"https://jira.mariadb.org/s/a9324d6758d385eb45c462685ad88f1d-CDN/lu2cib/820016/12ta74/c92c0caa9a024ae85b0ebdbed7fb4bd7/_/download/contextbatch/js/atl.global,-_super/batch.js?locale=en","startTime":604.1999998092651,"connectEnd":604.1999998092651,"connectStart":604.1999998092651,"domainLookupEnd":604.1999998092651,"domainLookupStart":604.1999998092651,"fetchStart":604.1999998092651,"redirectEnd":0,"redirectStart":0,"requestStart":604.1999998092651,"responseEnd":1112.5,"responseStart":1112.5,"secureConnectionStart":604.1999998092651},{"duration":508.5999994277954,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-en/jira.webresources:calendar-en.js","startTime":604.4000005722046,"connectEnd":604.4000005722046,"connectStart":604.4000005722046,"domainLookupEnd":604.4000005722046,"domainLookupStart":604.4000005722046,"fetchStart":604.4000005722046,"redirectEnd":0,"redirectStart":0,"requestStart":604.4000005722046,"responseEnd":1113,"responseStart":1113,"secureConnectionStart":604.4000005722046},{"duration":508.69999980926514,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-localisation-moment/jira.webresources:calendar-localisation-moment.js","startTime":604.6000003814697,"connectEnd":604.6000003814697,"connectStart":604.6000003814697,"domainLookupEnd":604.6000003814697,"domainLookupStart":604.6000003814697,"fetchStart":604.6000003814697,"redirectEnd":0,"redirectStart":0,"requestStart":604.6000003814697,"responseEnd":1113.3000001907349,"responseStart":1113.3000001907349,"secureConnectionStart":604.6000003814697},{"duration":552.2000007629395,"initiatorType":"link","name":"https://jira.mariadb.org/s/b04b06a02d1959df322d9cded3aeecc1-CDN/lu2cib/820016/12ta74/a2ff6aa845ffc9a1d22fe23d9ee791fc/_/download/contextbatch/css/jira.global.look-and-feel,-_super/batch.css","startTime":604.6999998092651,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":604.6999998092651,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1156.9000005722046,"responseStart":0,"secureConnectionStart":0},{"duration":508.8999996185303,"initiatorType":"script","name":"https://jira.mariadb.org/rest/api/1.0/shortcuts/820016/47140b6e0a9bc2e4913da06536125810/shortcuts.js?context=issuenavigation&context=issueaction","startTime":604.9000005722046,"connectEnd":604.9000005722046,"connectStart":604.9000005722046,"domainLookupEnd":604.9000005722046,"domainLookupStart":604.9000005722046,"fetchStart":604.9000005722046,"redirectEnd":0,"redirectStart":0,"requestStart":604.9000005722046,"responseEnd":1113.8000001907349,"responseStart":1113.8000001907349,"secureConnectionStart":604.9000005722046},{"duration":551.8999996185303,"initiatorType":"link","name":"https://jira.mariadb.org/s/3ac36323ba5e4eb0af2aa7ac7211b4bb-CDN/lu2cib/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/css/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.css?jira.create.linked.issue=true","startTime":605.1000003814697,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":605.1000003814697,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1157,"responseStart":0,"secureConnectionStart":0},{"duration":509.20000076293945,"initiatorType":"script","name":"https://jira.mariadb.org/s/5d5e8fe91fbc506585e83ea3b62ccc4b-CDN/lu2cib/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/js/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.js?jira.create.linked.issue=true&locale=en","startTime":605.1999998092651,"connectEnd":605.1999998092651,"connectStart":605.1999998092651,"domainLookupEnd":605.1999998092651,"domainLookupStart":605.1999998092651,"fetchStart":605.1999998092651,"redirectEnd":0,"redirectStart":0,"requestStart":605.1999998092651,"responseEnd":1114.4000005722046,"responseStart":1114.4000005722046,"secureConnectionStart":605.1999998092651},{"duration":980.3000001907349,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-js/jira.webresources:bigpipe-js.js","startTime":606.1999998092651,"connectEnd":606.1999998092651,"connectStart":606.1999998092651,"domainLookupEnd":606.1999998092651,"domainLookupStart":606.1999998092651,"fetchStart":606.1999998092651,"redirectEnd":0,"redirectStart":0,"requestStart":606.1999998092651,"responseEnd":1586.5,"responseStart":1586.5,"secureConnectionStart":606.1999998092651},{"duration":1642.3000001907349,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-init/jira.webresources:bigpipe-init.js","startTime":606.1999998092651,"connectEnd":606.1999998092651,"connectStart":606.1999998092651,"domainLookupEnd":606.1999998092651,"domainLookupStart":606.1999998092651,"fetchStart":606.1999998092651,"redirectEnd":0,"redirectStart":0,"requestStart":606.1999998092651,"responseEnd":2248.5,"responseStart":2248.5,"secureConnectionStart":606.1999998092651},{"duration":418.0999994277954,"initiatorType":"xmlhttprequest","name":"https://jira.mariadb.org/rest/webResources/1.0/resources","startTime":1169.1000003814697,"connectEnd":1169.1000003814697,"connectStart":1169.1000003814697,"domainLookupEnd":1169.1000003814697,"domainLookupStart":1169.1000003814697,"fetchStart":1169.1000003814697,"redirectEnd":0,"redirectStart":0,"requestStart":1169.1000003814697,"responseEnd":1587.1999998092651,"responseStart":1587.1999998092651,"secureConnectionStart":1169.1000003814697},{"duration":842.8000001907349,"initiatorType":"script","name":"https://www.google-analytics.com/analytics.js","startTime":1470.6000003814697,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":1470.6000003814697,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":2313.4000005722046,"responseStart":0,"secureConnectionStart":0}],"fetchStart":0,"domainLookupStart":0,"domainLookupEnd":0,"connectStart":0,"connectEnd":0,"requestStart":443,"responseStart":597,"responseEnd":600,"domLoading":601,"domInteractive":2275,"domContentLoadedEventStart":2275,"domContentLoadedEventEnd":2313,"domComplete":2715,"loadEventStart":2715,"loadEventEnd":2716,"userAgent":"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)","marks":[{"name":"bigPipe.sidebar-id.start","time":2261.6000003814697},{"name":"bigPipe.sidebar-id.end","time":2262.5},{"name":"bigPipe.activity-panel-pipe-id.start","time":2262.699999809265},{"name":"bigPipe.activity-panel-pipe-id.end","time":2263.199999809265},{"name":"activityTabFullyLoaded","time":2318.699999809265}],"measures":[],"correlationId":"82c74ad80cb2a1","effectiveType":"4g","downlink":9.3,"rtt":0,"serverDuration":98,"dbReadsTimeInMs":16,"dbConnsTimeInMs":26,"applicationHash":"9d11dbea5f4be3d4cc21f03a88dd11d8c8687422","experiments":[]}}