CVE-2014-2436
published 2014-04-16CVE-2014-2436: Unspecified vulnerability in Oracle MySQL Server 5.5.36 and earlier and 5.6.16 and earlier allows remote authenticated users to affect confidentiality…
medium6.5CVSS 3.1
AVNACLAuSCPIPAP
Unspecified vulnerability in Oracle MySQL Server 5.5.36 and earlier and 5.6.16 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to RBR.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mariadb | mariadb | >= 10.0.0 < 10.0.11 | 10.0.11 |
| mariadb | mariadb | >= 5.5.0 < 5.5.37 | 5.5.37 |
| oracle | mysql | 5.5.0 – 5.5.36 | — |
| oracle | mysql | 5.6.0 – 5.6.16 | — |
| oracle | solaris | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvd6.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv6.5MEDIUM
VulDB
Oracle MySQL Server up to 5.5.36/5.6.16 RBR privilege escalation (Nessus ID 74141 / ID 350399)
vuldb·2026-05-11·CVSS 6.5
CVE-2014-2436 [MEDIUM] Oracle MySQL Server up to 5.5.36/5.6.16 RBR privilege escalation (Nessus ID 74141 / ID 350399)
A vulnerability was found in Oracle MySQL Server up to 5.5.36/5.6.16. It has been declared as critical. Affected by this issue is some unknown functionality of the component RBR Handler. Executing a manipulation can lead to privilege escalation.
This vulnerability is registered as CVE-2014-2436. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
GHSA
GHSA-m3jx-759h-r3c9: Unspecified vulnerability in Oracle MySQL Server 5
ghsa_unreviewed·2022-05-13
CVE-2014-2436 [MEDIUM] GHSA-m3jx-759h-r3c9: Unspecified vulnerability in Oracle MySQL Server 5
Unspecified vulnerability in Oracle MySQL Server 5.5.36 and earlier and 5.6.16 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to RBR.
OSV
CVE-2014-2436: Unspecified vulnerability in Oracle MySQL Server 5
osv·2014-04-15·CVSS 6.5
CVE-2014-2436 [MEDIUM] CVE-2014-2436: Unspecified vulnerability in Oracle MySQL Server 5
Unspecified vulnerability in Oracle MySQL Server 5.5.36 and earlier and 5.6.16 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to RBR.
Ubuntu
MySQL vulnerabilities
vendor_ubuntu·2014-04-23
CVE-2014-0001 MySQL vulnerabilities
Title: MySQL vulnerabilities
Summary: Several security issues were fixed in MySQL.
Multiple security issues were discovered in MySQL and this update includes
a new upstream MySQL version to fix these issues. MySQL has been updated to
5.5.37.
In addition to security fixes, the updated packages contain bug fixes,
new features, and possibly incompatible changes.
Please see the following for more information:
http://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-36.html
http://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-37.html
http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html
Additionally, Matthias Reichl discovered that the mysql-5.5 packages were
missing the patches applied previously in the mysql-5.1 packages to drop
the default test database and localho
Red Hat
mysql: unspecified vulnerability related to RBR (CPU April 2014)
vendor_redhat·2014-04-15·CVSS 6.5
CVE-2014-2436 [MEDIUM] mysql: unspecified vulnerability related to RBR (CPU April 2014)
mysql: unspecified vulnerability related to RBR (CPU April 2014)
Unspecified vulnerability in Oracle MySQL Server 5.5.36 and earlier and 5.6.16 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to RBR.
Package: mysql (Red Hat Enterprise Linux 6) - Under investigation
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-2436 mysql: unspecified vulnerability related to RBR (CPU April 2014)
bugzilla·2014-04-16·CVSS 6.5
CVE-2014-2436 [MEDIUM] CVE-2014-2436 mysql: unspecified vulnerability related to RBR (CPU April 2014)
CVE-2014-2436 mysql: unspecified vulnerability related to RBR (CPU April 2014)
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: RBR). Supported versions that are affected are 5.5.36 and earlier and 5.6.16 and earlier. Difficult to exploit vulnerability allows successful authenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized takeover of MySQL Server possibly including arbitrary code execution within the MySQL Server.
External References:
http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html#AppendixMSQL
Discussion:
Created mariadb tracking bugs for this issue:
Affects: fedora-all [bug 1088234]
---
Created community-mysql tracking bugs for this issue:
Affects: fedora-all
Bugzilla
CVE-2014-2440 CVE-2014-0384 CVE-2014-2432 CVE-2014-2431 CVE-2014-2430 CVE-2014-2436 CVE-2014-2438 CVE-2014-2419 community-mysql: various flaws [fedora-all]
bugzilla·2014-04-16·CVSS 4.0
CVE-2014-2440 [MEDIUM] CVE-2014-2440 CVE-2014-0384 CVE-2014-2432 CVE-2014-2431 CVE-2014-2430 CVE-2014-2436 CVE-2014-2438 CVE-2014-2419 community-mysql: various flaws [fedora-all]
CVE-2014-2440 CVE-2014-0384 CVE-2014-2432 CVE-2014-2431 CVE-2014-2430 CVE-2014-2436 CVE-2014-2438 CVE-2014-2419 community-mysql: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM ch
Bugzilla
CVE-2014-2440 CVE-2014-0384 CVE-2014-2432 CVE-2014-2431 CVE-2014-2430 CVE-2014-2436 CVE-2014-2438 CVE-2014-2419 mariadb: various flaws [fedora-all]
bugzilla·2014-04-16·CVSS 4.0
CVE-2014-2440 [MEDIUM] CVE-2014-2440 CVE-2014-0384 CVE-2014-2432 CVE-2014-2431 CVE-2014-2430 CVE-2014-2436 CVE-2014-2438 CVE-2014-2419 mariadb: various flaws [fedora-all]
CVE-2014-2440 CVE-2014-0384 CVE-2014-2432 CVE-2014-2431 CVE-2014-2430 CVE-2014-2436 CVE-2014-2438 CVE-2014-2419 mariadb: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog
Bugzilla
CVE-2013-2436 OpenJDK: Wrapper.convert insufficient type checks (Libraries, 8009049)
bugzilla·2013-04-16·CVSS 9.3
CVE-2013-2436 [CRITICAL] CVE-2013-2436 OpenJDK: Wrapper.convert insufficient type checks (Libraries, 8009049)
CVE-2013-2436 OpenJDK: Wrapper.convert insufficient type checks (Libraries, 8009049)
It was discovered that the sun.util.invoke.Wrapper did not perform type checks correctly when converting wrapped values. An untrusted Java application or applet could possibly use this flaw to bypass Java sandbox restrictions.
Discussion:
Public now via Oracle Java SE CPU April 2014:
http://www.oracle.com/technetwork/topics/security/javacpuapr2013-1928497.html
Fixed in 7u21.
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2013:0752 https://rhn.redhat.com/errata/RHSA-2013-0752.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2013:0751 https://rhn.redhat.com/errata/RHSA-2013-0751.html
---
OpenJDK7 ups
http://rhn.redhat.com/errata/RHSA-2014-0522.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0536.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0537.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0702.htmlhttp://security.gentoo.org/glsa/glsa-201409-04.xmlhttp://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.htmlhttp://www.securityfocus.com/bid/66896http://rhn.redhat.com/errata/RHSA-2014-0522.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0536.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0537.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0702.htmlhttp://security.gentoo.org/glsa/glsa-201409-04.xmlhttp://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.htmlhttp://www.securityfocus.com/bid/66896
2014-04-16
Published