CVE-2014-2438: Low severity Oracle MySQL vulnerability
Published Apr 16, 2014
·Updated
Unspecified vulnerability in Oracle MySQL Server 5.5.35 and earlier and 5.6.15 and earlier allows remote authenticated users to affect availability via unknown vectors related to Replication.
Affected Software
21 affected components
Oracle MySQL>=5.5.0<=5.5.35
Oracle MySQL>=5.6.0<=5.6.15
MariaDB MariaDB>=5.5.0<5.5.36
MariaDB MariaDB>=10.0.0<10.0.9
redhat Enterprise Linux Desktop=5.0
redhat Enterprise Linux Desktop=7.0
redhat Enterprise Linux Eus=7.3
redhat Enterprise Linux Eus=7.4
redhat Enterprise Linux Eus=7.5
redhat Enterprise Linux Eus=7.6
redhat Enterprise Linux Eus=7.7
redhat Enterprise Linux Server=5.0
redhat Enterprise Linux Server=7.0
redhat Enterprise Linux Server Aus=7.3
redhat Enterprise Linux Server Aus=7.4
redhat Enterprise Linux Server Aus=7.6
redhat Enterprise Linux Server Aus=7.7
redhat Enterprise Linux Server Tus=7.3
redhat Enterprise Linux Server Tus=7.6
redhat Enterprise Linux Workstation=5.0
redhat Enterprise Linux Workstation=7.0
Event History
Apr 16, 2014
CVE Published
via MITRE·02:05 AM
Data Sourced
via MITRE·02:05 AM
Description
Data Sourced
via NVD·02:55 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-2438?
CVE-2014-2438 has a medium severity level, which could potentially affect server availability.
2
How do I fix CVE-2014-2438?
To fix CVE-2014-2438, upgrade to MySQL Server version 5.5.36 or later, or 5.6.16 or later.
3
Which versions of MySQL are affected by CVE-2014-2438?
CVE-2014-2438 affects MySQL Server versions 5.5.35 and earlier, and 5.6.15 and earlier.
4
Can CVE-2014-2438 be exploited remotely?
Yes, CVE-2014-2438 can be exploited by remote authenticated users.
5
What types of systems are affected by CVE-2014-2438?
CVE-2014-2438 affects Oracle MySQL Server as well as certain versions of MariaDB and Red Hat Enterprise Linux.