VID |
25153 |
Severity |
40 |
Port |
3306 |
Protocol |
TCP |
Class |
DB |
Detailed Description |
The version of MySQL installed on the remote host is earlier than 5.5.40 or 5.6.21 and is, therefore, potentially affected by the following vulnerabilities :
- C API SSL CERTIFICATE HANDLING - CLIENT:SSL:yaSSL - SERVER:DML - SERVER:INNODB DML FOREIGN KEYS - SERVER:OPTIMIZER - SERVER:SSL:yaSSL
* Note: This check solely relied on the banner of the remote MySQL server to assess this vulnerability, so this might be a false positive.
* References: http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html#AppendixMSQL
* Platforms Affected: MySQL versions 5.5 prior to 5.5.40 MySQL versions 5.6 prior to 5.6.21 Any operating system Any version |
Recommendation |
Upgrade to the latest version of MySQL (5.5.40 or 5.6.21 or later), available from the MySQL Web site at http://www.mysql.com/ |
Related URL |
CVE-2014-6464,CVE-2014-6469,CVE-2014-6491,CVE-2014-6494,CVE-2014-6496,CVE-2014-6500,CVE-2014-6507,CVE-2014-6555,CVE-2014-6559 (CVE) |
Related URL |
70444,70446,70451,70469,70478,70487,70497,70530,70550 (SecurityFocus) |
Related URL |
(ISS) |
|