The MySQL 5.5.39 and 5.6.20 releases fix an unspecified MyISAM temporary file issue: "MyISAM temporary files could be used to mount a code-execution attack. (Bug #18045646)" References: https://bugs.gentoo.org/show_bug.cgi?id=518718 http://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-39.html http://dev.mysql.com/doc/relnotes/mysql/5.6/en/news-5-6-20.html
Created mariadb tracking bugs for this issue: Affects: fedora-all [bug 1126274]
Created community-mysql tracking bugs for this issue: Affects: fedora-all [bug 1126273]
MySQL upstream commit: http://bazaar.launchpad.net/~mysql/mysql-server/5.5/revision/4638
mariadb-5.5.39-1.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report.
mariadb-5.5.39-1.fc19 has been pushed to the Fedora 19 stable repository. If problems still persist, please make note of it in this bug report.
Oracle assigned CVE-2014-4274 to this issue: http://seclists.org/oss-sec/2014/q3/556
The following issue has been fixed in MySQL: "Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: SERVER:MyISAM). Supported versions that are affected are 5.5.38 and earlier and 5.6.19 and earlier. Difficult to exploit vulnerability requiring logon to Operating System plus additional login/authentication to component or subcomponent. Successful attack of this vulnerability can escalate attacker privileges resulting in unauthorized takeover of MySQL Server possibly including arbitrary code execution within the MySQL Server." References: http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html
This issue has been addressed in the following products: Red Hat Enterprise Linux 5 Via RHSA-2014:1859 https://rhn.redhat.com/errata/RHSA-2014-1859.html
This issue has been addressed in the following products: Red Hat Software Collections 1 for Red Hat Enterprise Linux 7 Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.5 EUS Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.6 EUS Red Hat Software Collections 1 for Red Hat Enterprise Linux 6 Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.4 EUS Via RHSA-2014:1862 https://rhn.redhat.com/errata/RHSA-2014-1862.html
This issue has been addressed in the following products: Red Hat Software Collections 1 for Red Hat Enterprise Linux 7 Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.5 EUS Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.6 EUS Red Hat Software Collections 1 for Red Hat Enterprise Linux 6 Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.4 EUS Via RHSA-2014:1860 https://rhn.redhat.com/errata/RHSA-2014-1860.html
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2014:1861 https://rhn.redhat.com/errata/RHSA-2014-1861.html
This issue has been addressed in the following products: OpenStack 5 for RHEL 6 Via RHSA-2014:1937 https://rhn.redhat.com/errata/RHSA-2014-1937.html
This issue has been addressed in the following products: OpenStack 5 for RHEL 7 Via RHSA-2014:1940 https://rhn.redhat.com/errata/RHSA-2014-1940.html
mariadb-galera-5.5.40-2.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report.