Synced 30 Sept 2026 20:54 UTC Account
← All products

CVE-2013-1861

MEDIUM severity · CVSS 5 · Memory corruption
5CVSS MEDIUM

Summary

MariaDB 5.5.x before 5.5.30, 5.3.x before 5.3.13, 5.2.x before 5.2.15, and 5.1.x before 5.1.68, and Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote attackers to cause a denial of service (crash) via a crafted geometry feature that specifies a large number of points, which is not properly handled when processing the binary representation of this feature, related to a numeric calculation error.

Impact & exploitability

Attack vectorNetwork
Attack complexityLow
Privileges required—
User interaction—
Confidentiality impactNone
Integrity impactNone
Availability impact—
Exploit probability (EPSS)19%

AV:N/AC:L/Au:N/C:N/I:N/A:P

Affected products we track (3)

Recommendation

Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.