Oracle MySQL Server Geometry Query Processing Denial of Service Vulnerability

  Severity: MEDIUM
  CVE Identifier: CVE-2013-1861
  Advisory Date: JUL 21, 2015

  DESCRIPTION

MariaDB 5.5.x before 5.5.30, 5.3.x before 5.3.13, 5.2.x before 5.2.15, and 5.1.x before 5.1.68, and Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote attackers to cause a denial of service (crash) via a crafted geometry feature that specifies a large number of points, which is not properly handled when processing the binary representation of this feature, related to a numeric calculation error.

  TREND MICRO PROTECTION INFORMATION

Apply associated Trend Micro DPI Rules.

  SOLUTION

  Trend Micro Deep Security DPI Rule Number: 1005433
  Trend Micro Deep Security DPI Rule Name: 1005433 - Oracle MySQL Server Geometry Query Processing Denial Of Service Vulnerability

  AFFECTED SOFTWARE AND VERSION

  • mariadb mariadb 5.1.41
  • mariadb mariadb 5.1.42
  • mariadb mariadb 5.1.44
  • mariadb mariadb 5.1.47
  • mariadb mariadb 5.1.49
  • mariadb mariadb 5.1.50
  • mariadb mariadb 5.1.51
  • mariadb mariadb 5.1.53
  • mariadb mariadb 5.1.55
  • mariadb mariadb 5.1.60
  • mariadb mariadb 5.1.61
  • mariadb mariadb 5.1.62
  • mariadb mariadb 5.1.66
  • mariadb mariadb 5.1.67
  • mariadb mariadb 5.2.0
  • mariadb mariadb 5.2.1
  • mariadb mariadb 5.2.10
  • mariadb mariadb 5.2.11
  • mariadb mariadb 5.2.12
  • mariadb mariadb 5.2.13
  • mariadb mariadb 5.2.14
  • mariadb mariadb 5.2.2
  • mariadb mariadb 5.2.3
  • mariadb mariadb 5.2.4
  • mariadb mariadb 5.2.5
  • mariadb mariadb 5.2.6
  • mariadb mariadb 5.2.7
  • mariadb mariadb 5.2.8
  • mariadb mariadb 5.2.9
  • mariadb mariadb 5.3.0
  • mariadb mariadb 5.3.1
  • mariadb mariadb 5.3.10
  • mariadb mariadb 5.3.11
  • mariadb mariadb 5.3.12
  • mariadb mariadb 5.3.2
  • mariadb mariadb 5.3.3
  • mariadb mariadb 5.3.4
  • mariadb mariadb 5.3.5
  • mariadb mariadb 5.3.6
  • mariadb mariadb 5.3.7
  • mariadb mariadb 5.3.8
  • mariadb mariadb 5.3.9
  • mariadb mariadb 5.5.20
  • mariadb mariadb 5.5.21
  • mariadb mariadb 5.5.22
  • mariadb mariadb 5.5.23
  • mariadb mariadb 5.5.24
  • mariadb mariadb 5.5.25
  • mariadb mariadb 5.5.27
  • mariadb mariadb 5.5.28
  • mariadb mariadb 5.5.29
  • redhat enterprise_linux 5
  • redhat enterprise_linux 6