First published: Wed Jan 15 2014(Updated: )
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.71 and earlier, 5.5.33 and earlier, and 5.6.13 and earlier allows remote authenticated users to affect availability via unknown vectors related to Optimizer.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
MySQL | >=5.1.0<=5.1.71 | |
MySQL | >=5.5.0<=5.5.33 | |
MySQL | >=5.6.0<=5.6.13 | |
MariaDB | >=5.5.0<5.5.34 | |
MariaDB | >=10.0.0<10.0.7 | |
Ubuntu | =10.04 | |
Ubuntu | =12.04 | |
Ubuntu | =12.10 | |
Ubuntu | =13.10 | |
Debian Linux | =6.0 | |
Debian Linux | =7.0 | |
Red Hat Enterprise Linux Desktop | =5.0 | |
Red Hat Enterprise Linux Desktop | =6.0 | |
Red Hat Enterprise Linux Server EUS | =6.5 | |
Red Hat Enterprise Linux Server | =5.0 | |
Red Hat Enterprise Linux Server | =6.0 | |
Red Hat Enterprise Linux Server | =6.5 | |
Red Hat Enterprise Linux Server | =6.5 | |
Red Hat Enterprise Linux Workstation | =5.0 | |
Red Hat Enterprise Linux Workstation | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2014-0386 is generally considered medium, as it allows remote authenticated users to affect the availability of MySQL server.
To fix CVE-2014-0386, you should upgrade your MySQL server to a version later than 5.1.71, 5.5.33, or 5.6.13.
CVE-2014-0386 affects MySQL versions 5.1.71 and earlier, 5.5.33 and earlier, and 5.6.13 and earlier.
CVE-2014-0386 specifically targets Oracle MySQL and may not directly affect other database systems, but similar vulnerabilities could exist.
To mitigate the risks of CVE-2014-0386, limit user privileges and regularly update database software to the latest stable versions.