PT-2014-1198 · Oracle+5 · Mysql Server+5

Published

2014-01-15

·

Updated

2022-09-16

·

CVE-2014-0437

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Oracle MySQL versions 5.1.72 and earlier Oracle MySQL versions 5.5.34 and earlier Oracle MySQL versions 5.6.14 and earlier
Description The issue is related to the MySQL Server component in Oracle MySQL, specifically the Optimizer subcomponent. It allows remote authenticated users to impact data availability. The estimated number of potentially affected devices and details about real-world incidents are not provided.
Recommendations For Oracle MySQL versions 5.1.72 and earlier, update to a version later than 5.1.72 to resolve the issue. For Oracle MySQL versions 5.5.34 and earlier, update to a version later than 5.5.34 to resolve the issue. For Oracle MySQL versions 5.6.14 and earlier, update to a version later than 5.6.14 to resolve the issue. As a temporary workaround, consider restricting access to the Optimizer subcomponent until a patch is available.

Fix

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1152
ALT-PU-2015-1749
BDU:2014-00356
CESA-2014_0164
CESA-2014_0173
CESA-2014_0189
CVE-2014-0437
DSA-2845-1
DSA-2848-1
RHSA-2014:0164
RHSA-2014:0173
RHSA-2014:0186
RHSA-2014:0189
RHSA-2014_0164
RHSA-2014_0186

Affected Products

Alt Linux
Centos
Mariadb Server
Mysql Server
Red Hat
Suse