CVE-2014-4260: Medium severity Oracle MySQL vulnerability
Published Jul 17, 2014
·Updated
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier, and 5.6.17 and earlier, allows remote authenticated users to affect integrity and availability via vectors related to SRCHAR.
Affected Software
14 affected components
Oracle MySQL>=5.5.0<=5.5.37
Oracle MySQL>=5.6.0<=5.6.17
Oracle Solaris=11.3
Debian Debian Linux=7.0
SUSE Linux Enterprise Desktop=11-sp3
SUSE Linux Enterprise Desktop=12
SUSE Linux Enterprise Server=11-sp3
SUSE Linux Enterprise Server Vmware=11-sp3
SUSE Linux Enterprise Server=12
SUSE Linux Enterprise Software Development Kit=11-sp3
SUSE Linux Enterprise Software Development Kit=12
SUSE Linux Enterprise Workstation Extension=12
MariaDB MariaDB>=5.5.0<5.5.38
MariaDB MariaDB>=10.0.0<10.0.12
Event History
Jul 17, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4260?
CVE-2014-4260 is rated as a medium severity vulnerability that affects the integrity and availability of MySQL Server.
2
How do I fix CVE-2014-4260?
To mitigate CVE-2014-4260, update to a version of MySQL Server that is newer than 5.6.17 or 5.5.37.
3
Who is affected by CVE-2014-4260?
CVE-2014-4260 affects remote authenticated users of Oracle MySQL versions 5.5.37 and earlier, and 5.6.17 and earlier.
4
What components are involved in CVE-2014-4260?
CVE-2014-4260 involves the MySQL Server component in Oracle's database software.
5
Can CVE-2014-4260 be exploited remotely?
Yes, CVE-2014-4260 can be exploited by remote authenticated users.