Red Hat Bugzilla – Bug 1153484
CVE-2014-6494 mysql: unspecified vulnerability related to CLIENT:SSL:yaSSL (CPU October 2014)
Last modified: 2016-04-26 17:13:27 EDT
The following issue has been fixed in MySQL: "Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote attackers to affect availability via vectors related to CLIENT:SSL:yaSSL, a different vulnerability than CVE-2014-6496." References: http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html
MySQL packages in Red Hat Enterprise Linux and Fedora are built against system OpenSSL and do not use bundled yaSSL. Hence they can not be affected by any yaSSL issues. Statement: This issue did not affect the versions of mysql as shipped with Red Hat Enterprise Linux 5, 6, and 7, as they use system OpenSSL library rather than yaSSL.