7.5
CVE-2014-0001
- EPSS 6.35%
- Veröffentlicht 31.01.2014 23:55:04
- Zuletzt bearbeitet 29.04.2026 01:13:23
- Erkennungen
Buffer overflow in client/mysql.cc in Oracle MySQL and MariaDB before 5.5.35 allows remote database servers to cause a denial of service (crash) and possibly execute arbitrary code via a long server version string.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Enterprise Linux Version 5
Redhat ≫ Enterprise Linux Version 5 Edition client_workstation
Redhat ≫ Enterprise Linux Version 5 Edition server
Redhat ≫ Enterprise Linux Version 6.0
Redhat ≫ Enterprise Linux Desktop Version 5.0
Redhat ≫ Enterprise Linux Desktop Version 6.0
Redhat ≫ Enterprise Linux Server Version 6.0
Redhat ≫ Enterprise Linux Workstation Version 6.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 6.35% | 0.928 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
http://security.gentoo.org/glsa/glsa-201409-04.xml
http://rhn.redhat.com/errata/RHSA-2014-0173.html
http://rhn.redhat.com/errata/RHSA-2014-0186.html
http://rhn.redhat.com/errata/RHSA-2014-0189.html
http://rhn.redhat.com/errata/RHSA-2014-0164.html
http://bazaar.launchpad.net/~maria-captains/maria/5.5/revision/2502.565.64
http://osvdb.org/102713
http://secunia.com/advisories/52161
http://www.mandriva.com/security/advisories?name=MDVSA-2014:029
http://www.osvdb.org/102714
http://www.securityfocus.com/bid/65298
http://www.securitytracker.com/id/1029708
https://bugzilla.redhat.com/show_bug.cgi?id=1054592
https://exchange.xforce.ibmcloud.com/vulnerabilities/90901
https://mariadb.com/kb/en/mariadb-5535-changelog/