First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 185333
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Hanno Boeck <hanno@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 185333 depends on: Show dependency tree
Bug 185333 blocks:
Votes: 0    Show votes for this bug    Vote for this bug

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2007-07-14 17:22 0000
From changelog: 
Security fix: A malformed password packet in the connection protocol could
cause the server to crash. Thanks for Dormando for reporting this bug and
providing details and a proof of concept. (Bug#28984) 
Security Fix: CREATE TABLE LIKE did not require any privileges on the source
table. Now it requires the SELECT privilege. (Bug#25578) 
 In addition, CREATE TABLE LIKE was not isolated from alteration by other
connections, which resulted in various errors and incorrect binary log order
when trying to execute concurrently a CREATE TABLE LIKE statement and either
DDL statements on the source table or DML or DDL statements on the target
table. (Bug#23667)

------- Comment #1 From Robin Johnson 2007-07-14 20:48:45 0000 -------
Please try get the package version matrix right. The fixes/issues are in the
upstream releases that I corrected the summary to.

http://dev.mysql.com/doc/refman/5.0/en/releasenotes-es-5-0-44.html
http://dev.mysql.com/doc/refman/5.0/en/releasenotes-cs-5-0-45.html

We have enterprise 5.0.44 in the tree already, but not community 5.0.45.
I'll try to have the new community version in the tree before the end of the
weekend.

------- Comment #2 From Robin Johnson 2007-07-15 00:32:35 0000 -------
community-5.0.45 in CVS now.
I'll post testing instructions for arches in a moment.

------- Comment #3 From Robin Johnson 2007-07-15 00:42:47 0000 -------
Testing procedures:
FEATURES='userpriv test' USE='ssl cluster extraengine' emerge =mysql-5.0.44
FEATURES='userpriv test' USE='ssl cluster extraengine' emerge
=mysql-community-5.0.45

There should be _no_ failures at all this time. All past failures accounted for
and handled. I can complete the tests on my machines (ppc64-32ul, x86, amd64).

Target keywords:
mysql: alpha amd64 arm hppa ia64 ppc ppc64 s390 sh sparc x86
mysql-community: (none, the package is ~arch only).

------- Comment #4 From Sune Kloppenborg Jeppesen 2007-07-15 10:41:22 0000 -------
Arches please test and mark stable.

------- Comment #5 From Raúl Porcel 2007-07-15 16:47:35 0000 -------
alpha/ia64/x86 after a lot of time passing the tests

------- Comment #6 From Robin Johnson 2007-07-15 22:04:10 0000 -------
dercorny asked me about the 5.0.44-r1 version I have in the tree. It runs the
identical tests that 5.0.44 does, just moving some more bits into the eclass.
It should have the identical result as plain 5.0.44, so feel free to test
either.

------- Comment #7 From Stefan Cornelius (RETIRED) 2007-07-16 09:14:20 0000 -------
*** Bug 185506 has been marked as a duplicate of this bug. ***

------- Comment #8 From Markus Rothe 2007-07-16 19:36:05 0000 -------
5.0.44-r1 ppc64 stable

------- Comment #9 From Tobias Scherbaum 2007-07-16 20:03:32 0000 -------
ppc stable

------- Comment #10 From Jeroen Roovers 2007-07-16 21:32:54 0000 -------
dev-db/mysql-5.0.44-r1 stable for HPPA.

------- Comment #11 From Gustavo Zacarias (RETIRED) 2007-07-17 12:57:17 0000 -------
sparc stable.

------- Comment #12 From Steve Dibb 2007-07-28 18:03:16 0000 -------
amd64 stable

------- Comment #13 From Pierre-Yves Rofes 2007-07-28 18:36:51 0000 -------
time for glsa decision. I tend to vote yes because of the server crash.

------- Comment #14 From Sune Kloppenborg Jeppesen 2007-07-29 20:48:02 0000 -------
I vote YES.

------- Comment #15 From Raphael Marichez 2007-07-29 22:18:30 0000 -------
Same than the last MySQL security bug, i don't understand why we don't use
mysqld_safe to automatically restart mysqld... voting GLSA, since the server is
shut down...

------- Comment #16 From Raphael Marichez 2007-08-16 22:05:24 0000 -------
GLSA 200708-10, sorry for the delay...

First Last Prev Next    No search results available      Search page      Enter new bug