CVE-2014-4260
Summary
| CVE | CVE-2014-4260 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-07-17 11:17:00 UTC |
| Updated | 2022-07-19 17:03:00 UTC |
| Description | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier, and 5.6.17 and earlier, allows remote authenticated users to affect integrity and availability via vectors related to SRCHAR. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 7.0 | All | All | All |
| Operating System | Debian | Debian Linux | 7.0 | All | All | All |
| Application | Mariadb | Mariadb | All | All | All | All |
| Application | Oracle | Mysql | 5.5.0 | All | All | All |
| Application | Oracle | Mysql | 5.5.1 | All | All | All |
| Application | Oracle | Mysql | 5.5.10 | All | All | All |
| Application | Oracle | Mysql | 5.5.11 | All | All | All |
| Application | Oracle | Mysql | 5.5.12 | All | All | All |
| Application | Oracle | Mysql | 5.5.13 | All | All | All |
| Application | Oracle | Mysql | 5.5.14 | All | All | All |
| Application | Oracle | Mysql | 5.5.15 | All | All | All |
| Application | Oracle | Mysql | 5.5.16 | All | All | All |
| Application | Oracle | Mysql | 5.5.17 | All | All | All |
| Application | Oracle | Mysql | 5.5.18 | All | All | All |
| Application | Oracle | Mysql | 5.5.19 | All | All | All |
| Application | Oracle | Mysql | 5.5.2 | All | All | All |
| Application | Oracle | Mysql | 5.5.20 | All | All | All |
| Application | Oracle | Mysql | 5.5.21 | All | All | All |
| Application | Oracle | Mysql | 5.5.22 | All | All | All |
| Application | Oracle | Mysql | 5.5.23 | All | All | All |
| Application | Oracle | Mysql | 5.5.24 | All | All | All |
| Application | Oracle | Mysql | 5.5.25 | All | All | All |
| Application | Oracle | Mysql | 5.5.25 | a | All | All |
| Application | Oracle | Mysql | 5.5.26 | All | All | All |
| Application | Oracle | Mysql | 5.5.27 | All | All | All |
| Application | Oracle | Mysql | 5.5.28 | All | All | All |
| Application | Oracle | Mysql | 5.5.29 | All | All | All |
| Application | Oracle | Mysql | 5.5.3 | All | All | All |
| Application | Oracle | Mysql | 5.5.30 | All | All | All |
| Application | Oracle | Mysql | 5.5.31 | All | All | All |
| Application | Oracle | Mysql | 5.5.32 | All | All | All |
| Application | Oracle | Mysql | 5.5.33 | All | All | All |
| Application | Oracle | Mysql | 5.5.34 | All | All | All |
| Application | Oracle | Mysql | 5.5.35 | All | All | All |
| Application | Oracle | Mysql | 5.5.36 | All | All | All |
| Application | Oracle | Mysql | 5.5.4 | All | All | All |
| Application | Oracle | Mysql | 5.5.5 | All | All | All |
| Application | Oracle | Mysql | 5.5.6 | All | All | All |
| Application | Oracle | Mysql | 5.5.7 | All | All | All |
| Application | Oracle | Mysql | 5.5.9 | All | All | All |
| Application | Oracle | Mysql | 5.6.0 | All | All | All |
| Application | Oracle | Mysql | 5.6.1 | All | All | All |
| Application | Oracle | Mysql | 5.6.10 | All | All | All |
| Application | Oracle | Mysql | 5.6.11 | All | All | All |
| Application | Oracle | Mysql | 5.6.12 | All | All | All |
| Application | Oracle | Mysql | 5.6.13 | All | All | All |
| Application | Oracle | Mysql | 5.6.14 | All | All | All |
| Application | Oracle | Mysql | 5.6.15 | All | All | All |
| Application | Oracle | Mysql | 5.6.16 | All | All | All |
| Application | Oracle | Mysql | 5.6.2 | All | All | All |
| Application | Oracle | Mysql | 5.6.3 | All | All | All |
| Application | Oracle | Mysql | 5.6.4 | All | All | All |
| Application | Oracle | Mysql | 5.6.5 | All | All | All |
| Application | Oracle | Mysql | 5.6.6 | All | All | All |
| Application | Oracle | Mysql | 5.6.7 | All | All | All |
| Application | Oracle | Mysql | 5.6.8 | All | All | All |
| Application | Oracle | Mysql | 5.6.9 | All | All | All |
| Application | Oracle | Mysql | 5.5.0 | All | All | All |
| Application | Oracle | Mysql | 5.5.1 | All | All | All |
| Application | Oracle | Mysql | 5.5.10 | All | All | All |
| Application | Oracle | Mysql | 5.5.11 | All | All | All |
| Application | Oracle | Mysql | 5.5.12 | All | All | All |
| Application | Oracle | Mysql | 5.5.13 | All | All | All |
| Application | Oracle | Mysql | 5.5.14 | All | All | All |
| Application | Oracle | Mysql | 5.5.15 | All | All | All |
| Application | Oracle | Mysql | 5.5.16 | All | All | All |
| Application | Oracle | Mysql | 5.5.17 | All | All | All |
| Application | Oracle | Mysql | 5.5.18 | All | All | All |
| Application | Oracle | Mysql | 5.5.19 | All | All | All |
| Application | Oracle | Mysql | 5.5.2 | All | All | All |
| Application | Oracle | Mysql | 5.5.20 | All | All | All |
| Application | Oracle | Mysql | 5.5.21 | All | All | All |
| Application | Oracle | Mysql | 5.5.22 | All | All | All |
| Application | Oracle | Mysql | 5.5.23 | All | All | All |
| Application | Oracle | Mysql | 5.5.24 | All | All | All |
| Application | Oracle | Mysql | 5.5.25 | All | All | All |
| Application | Oracle | Mysql | 5.5.25 | a | All | All |
| Application | Oracle | Mysql | 5.5.26 | All | All | All |
| Application | Oracle | Mysql | 5.5.27 | All | All | All |
| Application | Oracle | Mysql | 5.5.28 | All | All | All |
| Application | Oracle | Mysql | 5.5.29 | All | All | All |
| Application | Oracle | Mysql | 5.5.3 | All | All | All |
| Application | Oracle | Mysql | 5.5.30 | All | All | All |
| Application | Oracle | Mysql | 5.5.31 | All | All | All |
| Application | Oracle | Mysql | 5.5.32 | All | All | All |
| Application | Oracle | Mysql | 5.5.33 | All | All | All |
| Application | Oracle | Mysql | 5.5.34 | All | All | All |
| Application | Oracle | Mysql | 5.5.35 | All | All | All |
| Application | Oracle | Mysql | 5.5.36 | All | All | All |
| Application | Oracle | Mysql | 5.5.4 | All | All | All |
| Application | Oracle | Mysql | 5.5.5 | All | All | All |
| Application | Oracle | Mysql | 5.5.6 | All | All | All |
| Application | Oracle | Mysql | 5.5.7 | All | All | All |
| Application | Oracle | Mysql | 5.5.9 | All | All | All |
| Application | Oracle | Mysql | 5.6.0 | All | All | All |
| Application | Oracle | Mysql | 5.6.1 | All | All | All |
| Application | Oracle | Mysql | 5.6.10 | All | All | All |
| Application | Oracle | Mysql | 5.6.11 | All | All | All |
| Application | Oracle | Mysql | 5.6.12 | All | All | All |
| Application | Oracle | Mysql | 5.6.13 | All | All | All |
| Application | Oracle | Mysql | 5.6.14 | All | All | All |
| Application | Oracle | Mysql | 5.6.15 | All | All | All |
| Application | Oracle | Mysql | 5.6.16 | All | All | All |
| Application | Oracle | Mysql | 5.6.2 | All | All | All |
| Application | Oracle | Mysql | 5.6.3 | All | All | All |
| Application | Oracle | Mysql | 5.6.4 | All | All | All |
| Application | Oracle | Mysql | 5.6.5 | All | All | All |
| Application | Oracle | Mysql | 5.6.6 | All | All | All |
| Application | Oracle | Mysql | 5.6.7 | All | All | All |
| Application | Oracle | Mysql | 5.6.8 | All | All | All |
| Application | Oracle | Mysql | 5.6.9 | All | All | All |
| Application | Oracle | Mysql | All | All | All | All |
| Application | Oracle | Mysql | All | All | All | All |
| Operating System | Oracle | Solaris | 11.3 | All | All | All |
| Operating System | Oracle | Solaris | 11.3 | All | All | All |
| Operating System | Suse | Linux Enterprise Desktop | 11 | sp3 | All | All |
| Operating System | Suse | Linux Enterprise Desktop | 12 | - | All | All |
| Operating System | Suse | Linux Enterprise Server | 11 | sp3 | All | All |
| Operating System | Suse | Linux Enterprise Server | 11 | sp3 | All | All |
| Operating System | Suse | Linux Enterprise Server | 12 | - | All | All |
| Operating System | Suse | Linux Enterprise Software Development Kit | 11 | sp3 | All | All |
| Operating System | Suse | Linux Enterprise Software Development Kit | 12 | - | All | All |
| Operating System | Suse | Linux Enterprise Workstation Extension | 12 | All | All | All |
| Operating System | Suse | Suse Linux Enterprise Desktop | 11.0 | sp3 | All | All |
| Operating System | Suse | Suse Linux Enterprise Desktop | 11.0 | sp3 | All | All |
| Operating System | Suse | Suse Linux Enterprise Server | 11.0 | sp3 | All | All |
| Operating System | Suse | Suse Linux Enterprise Server | 11.0 | sp3 | All | All |
| Operating System | Suse | Suse Linux Enterprise Server | 11.0 | sp3 | All | All |
| Operating System | Suse | Suse Linux Enterprise Server | 11.0 | sp3 | All | All |
| Application | Suse | Suse Linux Enterprise Software Development Kit | 11.0 | sp3 | All | All |
| Application | Suse | Suse Linux Enterprise Software Development Kit | 11.0 | sp3 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| MySQL Multiple Bugs Let Remote Authenticated Users Partially Access and Modify Data and Partially Deny Service - SecurityTracker | SECTRACK | www.securitytracker.com | |
| [security-announce] SUSE-SU-2014:1072-1: important: Security update for | SUSE | lists.opensuse.org | Third Party Advisory |
| VMSA-2014-0012 | United States | CONFIRM | www.vmware.com | Third Party Advisory |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Debian -- Security Information -- DSA-2985-1 mysql-5.5 | DEBIAN | www.debian.org | Third Party Advisory |
| Oracle Solaris Third Party Bulletin - October 2015 | CONFIRM | www.oracle.com | Vendor Advisory |
| Full Disclosure: NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities | FULLDISC | seclists.org | Third Party Advisory |
| [security-announce] SUSE-SU-2015:0743-1: important: Security update for | SUSE | lists.opensuse.org | |
| Oracle MySQL Server CVE-2014-4260 Remote Security Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| About Secunia Research | Flexera | SECUNIA | secunia.com | |
| Oracle Critical Patch Update - July 2014 | CONFIRM | www.oracle.com | Vendor Advisory |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.