PT-2014-7290 · Oracle+6 · Mysql Server+6

Published

2014-10-09

·

Updated

2022-08-29

·

CVE-2014-6559

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Oracle MySQL Server versions 5.5.39 and earlier Oracle MySQL Server versions 5.6.20 and earlier
Description The issue allows remote attackers to affect confidentiality via vectors related to C API SSL CERTIFICATE HANDLING. This means that attackers can exploit the vulnerability to compromise the confidentiality of data.
Recommendations For Oracle MySQL Server versions 5.5.39 and earlier, update to a version later than 5.5.39 to resolve the issue. For Oracle MySQL Server versions 5.6.20 and earlier, update to a version later than 5.6.20 to resolve the issue. As a temporary workaround, consider restricting access to the C API SSL CERTIFICATE HANDLING functionality until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2015-1152
ALT-PU-2015-1749
CESA-2014_1861
CVE-2014-6559
DSA-3054-1
MGASA-2014-0424
OPENSUSE-SU-2015_1216-1
RHSA-2014:1859
RHSA-2014:1860
RHSA-2014:1861
RHSA-2014:1862
RHSA-2014:1937
RHSA-2014:1940
RHSA-2014_1859
RHSA-2014_1861
SUSE-SU-2015:0743-1
USN-2384-1

Affected Products

Alt Linux
Centos
Mariadb Server
Mysql Server
Red Hat
Suse
Ubuntu