Amazon Linux AMI : mysql51 (ALAS-2014-298)
High Nessus Plugin ID 72946
SynopsisThe remote Amazon Linux AMI host is missing a security update.
DescriptionThis update fixes several vulnerabilities in the MySQL database server. (CVE-2014-0386 , CVE-2014-0393 , CVE-2014-0401 , CVE-2014-0402 , CVE-2014-0412 , CVE-2014-0437 , CVE-2013-5908)
A buffer overflow flaw was found in the way the MySQL command line client tool (mysql) processed excessively long version strings. If a user connected to a malicious MySQL server via the mysql client, the server could use this flaw to crash the mysql client or, potentially, execute arbitrary code as the user running the mysql client.
SolutionRun 'yum update mysql51' to update your system.