CVE-2014-0001

Buffer overflow in client/mysql.cc in Oracle MySQL and MariaDB before 5.5.35 allows remote database servers to cause a denial of service (crash) and possibly execute arbitrary code via a long server version string.
References
Link Resource
http://bazaar.launchpad.net/~maria-captains/maria/5.5/revision/2502.565.64 Not Applicable
http://osvdb.org/102713 Broken Link
http://rhn.redhat.com/errata/RHSA-2014-0164.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2014-0173.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2014-0186.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2014-0189.html Third Party Advisory
http://secunia.com/advisories/52161
http://security.gentoo.org/glsa/glsa-201409-04.xml Patch Third Party Advisory VDB Entry
http://www.mandriva.com/security/advisories?name=MDVSA-2014:029 Broken Link
http://www.osvdb.org/102714 Broken Link
http://www.securityfocus.com/bid/65298 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1029708
https://bugzilla.redhat.com/show_bug.cgi?id=1054592 Issue Tracking Patch Third Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/90901
https://mariadb.com/kb/en/mariadb-5535-changelog/ Patch Vendor Advisory
http://bazaar.launchpad.net/~maria-captains/maria/5.5/revision/2502.565.64 Not Applicable
http://osvdb.org/102713 Broken Link
http://rhn.redhat.com/errata/RHSA-2014-0164.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2014-0173.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2014-0186.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2014-0189.html Third Party Advisory
http://secunia.com/advisories/52161
http://security.gentoo.org/glsa/glsa-201409-04.xml Patch Third Party Advisory VDB Entry
http://www.mandriva.com/security/advisories?name=MDVSA-2014:029 Broken Link
http://www.osvdb.org/102714 Broken Link
http://www.securityfocus.com/bid/65298 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1029708
https://bugzilla.redhat.com/show_bug.cgi?id=1054592 Issue Tracking Patch Third Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/90901
https://mariadb.com/kb/en/mariadb-5535-changelog/ Patch Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:redhat:enterprise_linux:5:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:5:*:client_workstation:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:5:*:server:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:oracle:mysql:5.5.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.3:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.4:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.5:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.6:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.7:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.9:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.10:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.11:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.12:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.13:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.14:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.15:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.16:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.17:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.18:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.19:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.20:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.21:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.22:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.23:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.24:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.25:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.25:a:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.26:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.27:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.28:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.29:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.30:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.31:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.32:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.33:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.34:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.35:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.36:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:a:oracle:mysql:5.6.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.6.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.6.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.6.3:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.6.4:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.6.5:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.6.6:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.6.7:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.6.8:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.6.9:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.6.10:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.6.11:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.6.12:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.6.13:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.6.14:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.6.15:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.6.16:*:*:*:*:*:*:*

History

21 Nov 2024, 02:01

Type Values Removed Values Added
References () http://bazaar.launchpad.net/~maria-captains/maria/5.5/revision/2502.565.64 - Not Applicable () http://bazaar.launchpad.net/~maria-captains/maria/5.5/revision/2502.565.64 - Not Applicable
References () http://osvdb.org/102713 - Broken Link () http://osvdb.org/102713 - Broken Link
References () http://rhn.redhat.com/errata/RHSA-2014-0164.html - Third Party Advisory () http://rhn.redhat.com/errata/RHSA-2014-0164.html - Third Party Advisory
References () http://rhn.redhat.com/errata/RHSA-2014-0173.html - Third Party Advisory () http://rhn.redhat.com/errata/RHSA-2014-0173.html - Third Party Advisory
References () http://rhn.redhat.com/errata/RHSA-2014-0186.html - Third Party Advisory () http://rhn.redhat.com/errata/RHSA-2014-0186.html - Third Party Advisory
References () http://rhn.redhat.com/errata/RHSA-2014-0189.html - Third Party Advisory () http://rhn.redhat.com/errata/RHSA-2014-0189.html - Third Party Advisory
References () http://secunia.com/advisories/52161 - () http://secunia.com/advisories/52161 -
References () http://security.gentoo.org/glsa/glsa-201409-04.xml - Patch, Third Party Advisory, VDB Entry () http://security.gentoo.org/glsa/glsa-201409-04.xml - Patch, Third Party Advisory, VDB Entry
References () http://www.mandriva.com/security/advisories?name=MDVSA-2014:029 - Broken Link () http://www.mandriva.com/security/advisories?name=MDVSA-2014:029 - Broken Link
References () http://www.osvdb.org/102714 - Broken Link () http://www.osvdb.org/102714 - Broken Link
References () http://www.securityfocus.com/bid/65298 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/65298 - Third Party Advisory, VDB Entry
References () http://www.securitytracker.com/id/1029708 - () http://www.securitytracker.com/id/1029708 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=1054592 - Patch, Issue Tracking, Third Party Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=1054592 - Issue Tracking, Patch, Third Party Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/90901 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/90901 -
References () https://mariadb.com/kb/en/mariadb-5535-changelog/ - Patch, Vendor Advisory () https://mariadb.com/kb/en/mariadb-5535-changelog/ - Patch, Vendor Advisory

Information

Published : 2014-01-31 23:55

Updated : 2024-11-21 02:01


NVD link : CVE-2014-0001

Mitre link : CVE-2014-0001

CVE.ORG link : CVE-2014-0001


JSON object : View

Products Affected

redhat

  • enterprise_linux_workstation
  • enterprise_linux_server
  • enterprise_linux_desktop
  • enterprise_linux

mariadb

  • mariadb

oracle

  • mysql
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer