CVE-2014-6551: Low severity oracle solaris and zettabyte file system (zfs) vulnerability
Published Oct 15, 2014
·Updated
Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier and 5.6.19 and earlier allows local users to affect confidentiality via vectors related to CLIENT:MYSQLADMIN.
Affected Software
9 affected components
Oracle Solaris=11.3
Oracle MySQL>=5.5.0<=5.5.38
Oracle MySQL>=5.6.0<=5.6.19
MariaDB MariaDB>=5.5.0<5.5.39
MariaDB MariaDB>=10.0.0<10.0.13
SUSE Linux Enterprise Desktop=12
SUSE Linux Enterprise Server=12
SUSE Linux Enterprise Software Development Kit=12
SUSE Linux Enterprise Workstation Extension=12
Remediation
Event History
Oct 15, 2014
CVE Published
via MITRE·10:03 PM
Data Sourced
via MITRE·10:03 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-6551?
CVE-2014-6551 is considered a moderate severity vulnerability affecting Oracle MySQL Server and certain database implementations.
2
How do I fix CVE-2014-6551?
To mitigate CVE-2014-6551, update Oracle MySQL Server to versions later than 5.5.38 and 5.6.19.
3
Which versions of MySQL are affected by CVE-2014-6551?
CVE-2014-6551 affects Oracle MySQL Server versions 5.5.38 and earlier as well as 5.6.19 and earlier.
4
What impact does CVE-2014-6551 have on confidentiality?
CVE-2014-6551 may allow local users to affect the confidentiality of the database by exploiting vulnerabilities in MYSQLADMIN.
5
Are other databases also affected by CVE-2014-6551?
Yes, CVE-2014-6551 also impacts certain versions of MariaDB that are within the specified version ranges.