MySQL bug 13889741 (which is CVE-2012-3163) was, apparently, not completely fixed. A very similar test case finds new, much more dangerous, buffer overflows in acl_get() and check_grant_db_routine(). They allow to overwrite the buffer by an arbitrary number of bytes, not just by one as in bug 13889741. One can trivially put a shellcode there.
To exploit this one needs a valid low-privileged user account in the MariaDB (or MySQL) server.
This new vulnerability is registered as CVE-2012-5611
Reported upstream as http://bugs.mysql.com/bug.php?id=67685
Public disclosure: http://seclists.org/fulldisclosure/2012/Dec/4
There are no comments yet on this issue.
{"report":{"fcp":797,"ttfb":190.40000009536743,"pageVisibility":"visible","entityId":22101,"key":"jira.project.issue.view-issue","isInitial":true,"threshold":1000,"elementTimings":{},"userDeviceMemory":8,"userDeviceProcessors":64,"apdex":1,"journeyId":"cd316337-a32d-480c-9a67-b39fb948df79","navigationType":0,"readyForUser":857.1999998092651,"redirectCount":0,"resourceLoadedEnd":534.5999999046326,"resourceLoadedStart":195.7999997138977,"resourceTiming":[{"duration":28,"initiatorType":"link","name":"https://jira.mariadb.org/s/2c21342762a6a02add1c328bed317ffd-CDN/lu2cib/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/css/_super/batch.css","startTime":195.7999997138977,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":195.7999997138977,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":223.7999997138977,"responseStart":0,"secureConnectionStart":0},{"duration":28,"initiatorType":"link","name":"https://jira.mariadb.org/s/7ebd35e77e471bc30ff0eba799ebc151-CDN/lu2cib/820016/12ta74/494e4c556ecbb29f90a3d3b4f09cb99c/_/download/contextbatch/css/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true&whisper-enabled=true","startTime":196.19999980926514,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":196.19999980926514,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":224.19999980926514,"responseStart":0,"secureConnectionStart":0},{"duration":126.40000009536743,"initiatorType":"script","name":"https://jira.mariadb.org/s/0917945aaa57108d00c5076fea35e069-CDN/lu2cib/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/js/_super/batch.js?locale=en","startTime":196.2999997138977,"connectEnd":196.2999997138977,"connectStart":196.2999997138977,"domainLookupEnd":196.2999997138977,"domainLookupStart":196.2999997138977,"fetchStart":196.2999997138977,"redirectEnd":0,"redirectStart":0,"requestStart":230.2999997138977,"responseEnd":322.69999980926514,"responseStart":247.69999980926514,"secureConnectionStart":196.2999997138977},{"duration":145.69999980926514,"initiatorType":"script","name":"https://jira.mariadb.org/s/2d8175ec2fa4c816e8023260bd8c1786-CDN/lu2cib/820016/12ta74/494e4c556ecbb29f90a3d3b4f09cb99c/_/download/contextbatch/js/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en&slack-enabled=true&whisper-enabled=true","startTime":196.59999990463257,"connectEnd":196.59999990463257,"connectStart":196.59999990463257,"domainLookupEnd":196.59999990463257,"domainLookupStart":196.59999990463257,"fetchStart":196.59999990463257,"redirectEnd":0,"redirectStart":0,"requestStart":231.7999997138977,"responseEnd":342.2999997138977,"responseStart":246.90000009536743,"secureConnectionStart":196.59999990463257},{"duration":63.90000009536743,"initiatorType":"script","name":"https://jira.mariadb.org/s/a9324d6758d385eb45c462685ad88f1d-CDN/lu2cib/820016/12ta74/c92c0caa9a024ae85b0ebdbed7fb4bd7/_/download/contextbatch/js/atl.global,-_super/batch.js?locale=en","startTime":196.7999997138977,"connectEnd":196.7999997138977,"connectStart":196.7999997138977,"domainLookupEnd":196.7999997138977,"domainLookupStart":196.7999997138977,"fetchStart":196.7999997138977,"redirectEnd":0,"redirectStart":0,"requestStart":231.90000009536743,"responseEnd":260.69999980926514,"responseStart":259.90000009536743,"secureConnectionStart":196.7999997138977},{"duration":61.90000009536743,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-en/jira.webresources:calendar-en.js","startTime":197,"connectEnd":197,"connectStart":197,"domainLookupEnd":197,"domainLookupStart":197,"fetchStart":197,"redirectEnd":0,"redirectStart":0,"requestStart":231.90000009536743,"responseEnd":258.90000009536743,"responseStart":255.5,"secureConnectionStart":197},{"duration":62.69999980926514,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-localisation-moment/jira.webresources:calendar-localisation-moment.js","startTime":197.09999990463257,"connectEnd":197.09999990463257,"connectStart":197.09999990463257,"domainLookupEnd":197.09999990463257,"domainLookupStart":197.09999990463257,"fetchStart":197.09999990463257,"redirectEnd":0,"redirectStart":0,"requestStart":233.40000009536743,"responseEnd":259.7999997138977,"responseStart":259,"secureConnectionStart":197.09999990463257},{"duration":34.200000286102295,"initiatorType":"link","name":"https://jira.mariadb.org/s/b04b06a02d1959df322d9cded3aeecc1-CDN/lu2cib/820016/12ta74/a2ff6aa845ffc9a1d22fe23d9ee791fc/_/download/contextbatch/css/jira.global.look-and-feel,-_super/batch.css","startTime":197.2999997138977,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":197.2999997138977,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":231.5,"responseStart":0,"secureConnectionStart":0},{"duration":76.19999980926514,"initiatorType":"script","name":"https://jira.mariadb.org/rest/api/1.0/shortcuts/820016/47140b6e0a9bc2e4913da06536125810/shortcuts.js?context=issuenavigation&context=issueaction","startTime":197.5,"connectEnd":197.5,"connectStart":197.5,"domainLookupEnd":197.5,"domainLookupStart":197.5,"fetchStart":197.5,"redirectEnd":0,"redirectStart":0,"requestStart":235.19999980926514,"responseEnd":273.69999980926514,"responseStart":272.5,"secureConnectionStart":197.5},{"duration":36.09999990463257,"initiatorType":"link","name":"https://jira.mariadb.org/s/3ac36323ba5e4eb0af2aa7ac7211b4bb-CDN/lu2cib/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/css/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.css?jira.create.linked.issue=true","startTime":197.59999990463257,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":197.59999990463257,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":233.69999980926514,"responseStart":0,"secureConnectionStart":0},{"duration":98.60000038146973,"initiatorType":"script","name":"https://jira.mariadb.org/s/5d5e8fe91fbc506585e83ea3b62ccc4b-CDN/lu2cib/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/js/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.js?jira.create.linked.issue=true&locale=en","startTime":197.7999997138977,"connectEnd":197.7999997138977,"connectStart":197.7999997138977,"domainLookupEnd":197.7999997138977,"domainLookupStart":197.7999997138977,"fetchStart":197.7999997138977,"redirectEnd":0,"redirectStart":0,"requestStart":239.2999997138977,"responseEnd":296.40000009536743,"responseStart":294.7999997138977,"secureConnectionStart":197.7999997138977},{"duration":328.40000009536743,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-js/jira.webresources:bigpipe-js.js","startTime":205,"connectEnd":205,"connectStart":205,"domainLookupEnd":205,"domainLookupStart":205,"fetchStart":205,"redirectEnd":0,"redirectStart":0,"requestStart":293.7999997138977,"responseEnd":533.4000000953674,"responseStart":518.4000000953674,"secureConnectionStart":205},{"duration":329.40000009536743,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-init/jira.webresources:bigpipe-init.js","startTime":205.19999980926514,"connectEnd":205.19999980926514,"connectStart":205.19999980926514,"domainLookupEnd":205.19999980926514,"domainLookupStart":205.19999980926514,"fetchStart":205.19999980926514,"redirectEnd":0,"redirectStart":0,"requestStart":314.5,"responseEnd":534.5999999046326,"responseStart":521.6999998092651,"secureConnectionStart":205.19999980926514},{"duration":223.80000019073486,"initiatorType":"xmlhttprequest","name":"https://jira.mariadb.org/rest/webResources/1.0/resources","startTime":530.5999999046326,"connectEnd":530.5999999046326,"connectStart":530.5999999046326,"domainLookupEnd":530.5999999046326,"domainLookupStart":530.5999999046326,"fetchStart":530.5999999046326,"redirectEnd":0,"redirectStart":0,"requestStart":724,"responseEnd":754.4000000953674,"responseStart":753.6999998092651,"secureConnectionStart":530.5999999046326}],"fetchStart":1,"domainLookupStart":1,"domainLookupEnd":1,"connectStart":1,"connectEnd":1,"requestStart":44,"responseStart":191,"responseEnd":204,"domLoading":195,"domInteractive":913,"domContentLoadedEventStart":913,"domContentLoadedEventEnd":957,"domComplete":1310,"loadEventStart":1310,"loadEventEnd":1311,"userAgent":"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)","marks":[{"name":"bigPipe.sidebar-id.start","time":891.9000000953674},{"name":"bigPipe.sidebar-id.end","time":892.7999997138977},{"name":"bigPipe.activity-panel-pipe-id.start","time":893},{"name":"bigPipe.activity-panel-pipe-id.end","time":893.5999999046326},{"name":"activityTabFullyLoaded","time":963.5}],"measures":[],"correlationId":"a0550d4c641ade","effectiveType":"4g","downlink":9.7,"rtt":0,"serverDuration":92,"dbReadsTimeInMs":8,"dbConnsTimeInMs":17,"applicationHash":"9d11dbea5f4be3d4cc21f03a88dd11d8c8687422","experiments":[]}}