Name | CVE-2014-0001 |
Description | Buffer overflow in client/mysql.cc in Oracle MySQL and MariaDB before 5.5.35 allows remote database servers to cause a denial of service (crash) and possibly execute arbitrary code via a long server version string. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DLA-75-1, DSA-2919-1 |
Debian Bugs | 737596, 737597 |
The information below is based on the following data on fixed versions.
Notes
[squeeze] - mysql-5.1 <no-dsa> (Minor issue, currently not fixed in MySQL, can be included once fixed in 5.1.x)
https://bugzilla.redhat.com/show_bug.cgi?id=1054592
http://bazaar.launchpad.net/~maria-captains/maria/5.5/revision/2502.565.64