Release date:
Updated on:
Affected Systems:
Oracle MySQL Server <= 5.6.15
Description:
--------------------------------------------------------------------------------
Bugtraq id: 66863
CVE (CAN) ID: CVE-2014-2450
Oracle MySQL Server is a lightweight relational database system.
Oracle MySQL Server has a remote security vulnerability in the implementation of the MySQL Server component. This vulnerability can be exploited through the MySQL Server protocol. authenticated remote attackers can exploit this vulnerability to affect the availability of affected components. Versions affected by this vulnerability include 5.6.15 and earlier.
<* Source: Oracle
Link: http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Oracle
------
Oracle has released a Security Bulletin (cpuapr2014-1972952) and patches for this:
Cpuapr2014-1972952: Oracle Critical Patch Update Advisory-specification l 2014
Link: http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html
Patch download:
Https://support.oracle.com/rs? Type = doc & id = 1635913.1