---
title: "CVE-2012-5613\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2012-5613?format=md
keywords: index, follow
---

# CVE-2012-5613

Publication date 3 December 2012

Last updated 4 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly
other versions, when configured to assign the FILE privilege to users who
should not have administrative privileges, allows remote authenticated
users to gain privileges by leveraging the FILE privilege to create files
as the MySQL administrator. NOTE: the vendor disputes this issue, stating
that this is only a vulnerability when the administrator does not follow
recommendations in the product's installation documentation. NOTE: it could
be argued that this should not be included in CVE because it is a
configuration issue.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2012-5613?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| mysql-5.1 | 13.04 raring | Not in release |
| 12.10 quantal | Not in release |
| 12.04 LTS precise | Not in release |
| 11.10 oneiric | Ignored |
| 10.04 LTS lucid | Not in release |
| 8.04 LTS hardy | Not in release |
| mysql-5.5 | 13.04 raring | Ignored |
| 12.10 quantal | Ignored |
| 12.04 LTS precise | Ignored |
| 11.10 oneiric | Not in release |
| 10.04 LTS lucid | Not in release |
| 8.04 LTS hardy | Not in release |
| mysql-dfsg-5.1 | 13.04 raring | Not in release |
| 12.10 quantal | Not in release |
| 12.04 LTS precise | Not in release |
| 11.10 oneiric | Not in release |
| 10.04 LTS lucid | Ignored |
| 8.04 LTS hardy | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

as of 2013-05-01, no new version from upstream

---

### [seth-arnold](https://launchpad.net/~seth-arnold)

Not actually fixed in 1807-1 -- my mistake

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

This is disputed, marking as ignored

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5613)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2012-5613)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2012-5613)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2012-5613)

### Other references

* <http://seclists.org/fulldisclosure/2012/Dec/6>
* <http://www.openwall.com/lists/oss-security/2012/12/02/4>
* <http://www.openwall.com/lists/oss-security/2012/12/02/3>
* <https://www.cve.org/CVERecord?id=CVE-2012-5613>
