Bug 1126271 (CVE-2014-4274)
Summary: | CVE-2014-4274 mysql: unspecified MyISAM temporary file issue fixed in 5.5.39 and 5.6.20 | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Murray McAllister <mmcallis> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | byte, carnil, databases-maint, hhorak, jdornak, jorton, jstanek, mmaslano, vdanen |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | mysql 5.5.39, mysql 5.6.20 | Doc Type: | Bug Fix |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2014-12-17 06:02:48 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1126273, 1126274, 1160514, 1160515, 1160548, 1160549, 1160550, 1160551, 1160566, 1162374, 1162375 | ||
Bug Blocks: | 1153468, 1165433 |
Description
Murray McAllister
2014-08-04 04:16:16 UTC
Created mariadb tracking bugs for this issue: Affects: fedora-all [bug 1126274] Created community-mysql tracking bugs for this issue: Affects: fedora-all [bug 1126273] MySQL upstream commit: http://bazaar.launchpad.net/~mysql/mysql-server/5.5/revision/4638 mariadb-5.5.39-1.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report. mariadb-5.5.39-1.fc19 has been pushed to the Fedora 19 stable repository. If problems still persist, please make note of it in this bug report. Oracle assigned CVE-2014-4274 to this issue: http://seclists.org/oss-sec/2014/q3/556 The following issue has been fixed in MySQL: "Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: SERVER:MyISAM). Supported versions that are affected are 5.5.38 and earlier and 5.6.19 and earlier. Difficult to exploit vulnerability requiring logon to Operating System plus additional login/authentication to component or subcomponent. Successful attack of this vulnerability can escalate attacker privileges resulting in unauthorized takeover of MySQL Server possibly including arbitrary code execution within the MySQL Server." References: http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html This issue has been addressed in the following products: Red Hat Enterprise Linux 5 Via RHSA-2014:1859 https://rhn.redhat.com/errata/RHSA-2014-1859.html This issue has been addressed in the following products: Red Hat Software Collections 1 for Red Hat Enterprise Linux 7 Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.5 EUS Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.6 EUS Red Hat Software Collections 1 for Red Hat Enterprise Linux 6 Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.4 EUS Via RHSA-2014:1862 https://rhn.redhat.com/errata/RHSA-2014-1862.html This issue has been addressed in the following products: Red Hat Software Collections 1 for Red Hat Enterprise Linux 7 Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.5 EUS Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.6 EUS Red Hat Software Collections 1 for Red Hat Enterprise Linux 6 Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.4 EUS Via RHSA-2014:1860 https://rhn.redhat.com/errata/RHSA-2014-1860.html This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2014:1861 https://rhn.redhat.com/errata/RHSA-2014-1861.html This issue has been addressed in the following products: OpenStack 5 for RHEL 6 Via RHSA-2014:1937 https://rhn.redhat.com/errata/RHSA-2014-1937.html This issue has been addressed in the following products: OpenStack 5 for RHEL 7 Via RHSA-2014:1940 https://rhn.redhat.com/errata/RHSA-2014-1940.html mariadb-galera-5.5.40-2.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report. |