CVE-2014-4258
Summary
| CVE | CVE-2014-4258 |
|---|---|
| State | PUBLISHED |
| Assigner | oracle |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-07-17 11:17:10 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier and 5.6.17 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to SRINFOSC. |
Risk And Classification
Primary CVSS: v2.0 6.5 from [email protected]
AV:N/AC:L/Au:S/C:P/I:P/A:P
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 7.0 | All | All | All |
| Application | Mariadb | Mariadb | All | All | All | All |
| Operating System | Opensuse Project | Suse Linux Enterprise Desktop | 11.0 | sp3 | All | All |
| Operating System | Opensuse Project | Suse Linux Enterprise Server | 11.0 | sp3 | All | All |
| Operating System | Opensuse Project | Suse Linux Enterprise Server | 11.0 | sp3 | All | All |
| Operating System | Opensuse Project | Suse Linux Enterprise Software Development Kit | 11.0 | sp3 | All | All |
| Application | Oracle | Mysql | All | All | All | All |
| Application | Oracle | Mysql | All | All | All | All |
| Operating System | Oracle | Solaris | 11.3 | All | All | All |
| Application | Vmware | Vcenter Server Appliance | 5.0 | All | All | All |
| Application | Vmware | Vcenter Server Appliance | 5.0 | update_1 | All | All |
| Application | Vmware | Vcenter Server Appliance | 5.0 | update_2 | All | All |
| Application | Vmware | Vcenter Server Appliance | 5.1 | All | All | All |
| Application | Vmware | Vcenter Server Appliance | 5.1 | update_1 | All | All |
| Application | Vmware | Vcenter Server Appliance | 5.1 | update_2 | All | All |
| Application | Vmware | Vcenter Server Appliance | 5.5 | All | All | All |
| Application | Vmware | Vcenter Server Appliance | 5.5 | update_1 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Oracle MySQL Server CVE-2014-4258 Remote Security Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Not Applicable |
| Debian -- Security Information -- DSA-2985-1 mysql-5.5 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Third Party Advisory |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Oracle Critical Patch Update - July 2014 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Vendor Advisory |
| Oracle Solaris Third Party Bulletin - October 2015 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Vendor Advisory |
| MySQL Multiple Bugs Let Remote Authenticated Users Partially Access and Modify Data and Partially Deny Service - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Broken Link, Third Party Advisory, VDB Entry |
| Full Disclosure: NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | Mailing List, Third Party Advisory |
| [security-announce] SUSE-SU-2014:1072-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Mailing List, Third Party Advisory |
| VMSA-2014-0012 | United States | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | Third Party Advisory |
| [security-announce] SUSE-SU-2015:0743-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.