PT-2014-7290 · Oracle+6 · Mysql Server+6
Published
2014-10-09
·
Updated
2022-08-29
·
CVE-2014-6559
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle MySQL Server versions 5.5.39 and earlier
Oracle MySQL Server versions 5.6.20 and earlier
Description
The issue allows remote attackers to affect confidentiality via vectors related to C API SSL CERTIFICATE HANDLING. This means that attackers can exploit the vulnerability to compromise the confidentiality of data.
Recommendations
For Oracle MySQL Server versions 5.5.39 and earlier, update to a version later than 5.5.39 to resolve the issue.
For Oracle MySQL Server versions 5.6.20 and earlier, update to a version later than 5.6.20 to resolve the issue.
As a temporary workaround, consider restricting access to the C API SSL CERTIFICATE HANDLING functionality until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Mariadb Server
Mysql Server
Red Hat
Suse
Ubuntu