USN-2170-1

Source
https://ubuntu.com/security/notices/USN-2170-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-2170-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-2170-1
Upstream
Related
Published
2014-04-23T12:56:46Z
Modified
2026-02-10T04:40:48Z
Summary
mysql-5.5 vulnerabilities
Details

Multiple security issues were discovered in MySQL and this update includes a new upstream MySQL version to fix these issues. MySQL has been updated to 5.5.37.

In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes.

Please see the following for more information: http://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-36.html http://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-37.html http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html

Additionally, Matthias Reichl discovered that the mysql-5.5 packages were missing the patches applied previously in the mysql-5.1 packages to drop the default test database and localhost permissions granting access to any databases starting with "test_". This update reintroduces these patches for Ubuntu 12.04 LTS, Ubuntu 12.10, and Ubuntu 13.10. Existing test databases and permissions will not be modified on upgrade. To manually restrict access for existing installations, please refer to the following:

http://dev.mysql.com/doc/refman/5.5/en/default-privileges.html

References

Affected packages

Ubuntu:14.04:LTS / mysql-5.5

Package

Name
mysql-5.5
Purl
pkg:deb/ubuntu/mysql-5.5@5.5.37-0ubuntu0.14.04.1?arch=source&distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.5.37-0ubuntu0.14.04.1

Affected versions

5.*
5.5.32-0ubuntu7
5.5.34-0ubuntu1
5.5.34-0ubuntu2
5.5.35-0ubuntu1
5.5.35+dfsg-1ubuntu1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "5.5.37-0ubuntu0.14.04.1",
            "binary_name": "libmysqlclient-dev"
        },
        {
            "binary_version": "5.5.37-0ubuntu0.14.04.1",
            "binary_name": "libmysqlclient18"
        },
        {
            "binary_version": "5.5.37-0ubuntu0.14.04.1",
            "binary_name": "libmysqld-dev"
        },
        {
            "binary_version": "5.5.37-0ubuntu0.14.04.1",
            "binary_name": "libmysqld-pic"
        },
        {
            "binary_version": "5.5.37-0ubuntu0.14.04.1",
            "binary_name": "mysql-client"
        },
        {
            "binary_version": "5.5.37-0ubuntu0.14.04.1",
            "binary_name": "mysql-client-5.5"
        },
        {
            "binary_version": "5.5.37-0ubuntu0.14.04.1",
            "binary_name": "mysql-client-core-5.5"
        },
        {
            "binary_version": "5.5.37-0ubuntu0.14.04.1",
            "binary_name": "mysql-common"
        },
        {
            "binary_version": "5.5.37-0ubuntu0.14.04.1",
            "binary_name": "mysql-server"
        },
        {
            "binary_version": "5.5.37-0ubuntu0.14.04.1",
            "binary_name": "mysql-server-5.5"
        },
        {
            "binary_version": "5.5.37-0ubuntu0.14.04.1",
            "binary_name": "mysql-server-core-5.5"
        },
        {
            "binary_version": "5.5.37-0ubuntu0.14.04.1",
            "binary_name": "mysql-source-5.5"
        },
        {
            "binary_version": "5.5.37-0ubuntu0.14.04.1",
            "binary_name": "mysql-testsuite"
        },
        {
            "binary_version": "5.5.37-0ubuntu0.14.04.1",
            "binary_name": "mysql-testsuite-5.5"
        }
    ],
    "availability": "No subscription required"
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-2170-1.json"
cves_map
{
    "ecosystem": "Ubuntu:14.04:LTS",
    "cves": [
        {
            "id": "CVE-2014-0001",
            "severity": [
                {
                    "type": "Ubuntu",
                    "score": "low"
                }
            ]
        },
        {
            "id": "CVE-2014-0384",
            "severity": [
                {
                    "type": "Ubuntu",
                    "score": "low"
                }
            ]
        },
        {
            "id": "CVE-2014-2419",
            "severity": [
                {
                    "type": "Ubuntu",
                    "score": "low"
                }
            ]
        },
        {
            "id": "CVE-2014-2430",
            "severity": [
                {
                    "type": "Ubuntu",
                    "score": "low"
                }
            ]
        },
        {
            "id": "CVE-2014-2431",
            "severity": [
                {
                    "type": "Ubuntu",
                    "score": "low"
                }
            ]
        },
        {
            "id": "CVE-2014-2432",
            "severity": [
                {
                    "type": "Ubuntu",
                    "score": "low"
                }
            ]
        },
        {
            "id": "CVE-2014-2436",
            "severity": [
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        },
        {
            "id": "CVE-2014-2438",
            "severity": [
                {
                    "type": "Ubuntu",
                    "score": "low"
                }
            ]
        },
        {
            "id": "CVE-2014-2440",
            "severity": [
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        }
    ]
}