CVE-2014-0001

Buffer overflow in client/mysql.cc in Oracle MySQL and MariaDB before 5.5.35 allows remote database servers to cause a denial of service (crash) and possibly execute arbitrary code via a long server version string.
References
Link Resource
http://bazaar.launchpad.net/~maria-captains/maria/5.5/revision/2502.565.64 Not Applicable
http://osvdb.org/102713 Broken Link
http://rhn.redhat.com/errata/RHSA-2014-0164.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2014-0173.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2014-0186.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2014-0189.html Third Party Advisory
http://secunia.com/advisories/52161
http://security.gentoo.org/glsa/glsa-201409-04.xml Patch Third Party Advisory VDB Entry
http://www.mandriva.com/security/advisories?name=MDVSA-2014:029 Broken Link
http://www.osvdb.org/102714 Broken Link
http://www.securityfocus.com/bid/65298 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1029708
https://bugzilla.redhat.com/show_bug.cgi?id=1054592 Issue Tracking Patch Third Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/90901
https://mariadb.com/kb/en/mariadb-5535-changelog/ Patch Vendor Advisory
http://bazaar.launchpad.net/~maria-captains/maria/5.5/revision/2502.565.64 Not Applicable
http://osvdb.org/102713 Broken Link
http://rhn.redhat.com/errata/RHSA-2014-0164.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2014-0173.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2014-0186.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2014-0189.html Third Party Advisory
http://secunia.com/advisories/52161
http://security.gentoo.org/glsa/glsa-201409-04.xml Patch Third Party Advisory VDB Entry
http://www.mandriva.com/security/advisories?name=MDVSA-2014:029 Broken Link
http://www.osvdb.org/102714 Broken Link
http://www.securityfocus.com/bid/65298 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1029708
https://bugzilla.redhat.com/show_bug.cgi?id=1054592 Issue Tracking Patch Third Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/90901
https://mariadb.com/kb/en/mariadb-5535-changelog/ Patch Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:redhat:enterprise_linux:5:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:5:*:client_workstation:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:5:*:server:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:oracle:mysql:5.5.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.3:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.4:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.5:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.6:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.7:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.9:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.10:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.11:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.12:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.13:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.14:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.15:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.16:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.17:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.18:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.19:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.20:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.21:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.22:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.23:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.24:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.25:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.25:a:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.26:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.27:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.28:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.29:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.30:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.31:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.32:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.33:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.34:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.35:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.5.36:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:a:oracle:mysql:5.6.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.6.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.6.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.6.3:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.6.4:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.6.5:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.6.6:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.6.7:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.6.8:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.6.9:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.6.10:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.6.11:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.6.12:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.6.13:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.6.14:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.6.15:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql:5.6.16:*:*:*:*:*:*:*

History

No history.

Information

Published : 2014-01-31 23:55

Updated : 2025-04-11 00:51


NVD link : CVE-2014-0001

Mitre link : CVE-2014-0001

CVE.ORG link : CVE-2014-0001


JSON object : View

Products Affected

mariadb

  • mariadb

oracle

  • mysql

redhat

  • enterprise_linux_workstation
  • enterprise_linux
  • enterprise_linux_desktop
  • enterprise_linux_server
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer