Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 77805
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Sune Kloppenborg Jeppesen <jaervosz@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
mysql-4.1.8-bug77805.patch patch for mysql-4.1.8 modified from http://lists.mysql.com/internals/20600 patch Francesco R. (RETIRED) 2005-01-17 15:40 0000 3.31 KB Details | Diff
my-stuff-4.1.9.tar.gz 4.1.9 ebuild patches ewarn application/octet-stream francesco riosa 2005-01-20 16:48 0000 5.11 KB Details
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 77805 depends on: 78678 Show dependency tree
Bug 77805 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2005-01-13 03:37 0000
Issues reported by Javier Fernandez-Sanguino Pena and Debian Security Audit
Team.

------- Comment #1 From Thierry Carrez (RETIRED) 2005-01-13 09:07:36 0000 -------
This is CAN-2005-0004 and can be considered semi-public.
Robin: please apply fix to 4.0.23 and bump in portage ?

------- Comment #2 From Thierry Carrez (RETIRED) 2005-01-17 06:08:59 0000 -------
Public now @ http://secunia.com/advisories/13867/

------- Comment #3 From Francesco R. (RETIRED) 2005-01-17 15:40:34 0000 -------
Created an attachment (id=48789) [details]
patch for mysql-4.1.8 modified from http://lists.mysql.com/internals/20600

sligtly modified the patch reported in the url given.
It should apply cleanly on mysql-4.1.8 tree

------- Comment #4 From Jasmin Buchert 2005-01-17 18:31:14 0000 -------
Patch for mysql-4.1.8 also applys cleanly to mysql-4.1.9 (bug #78452).

------- Comment #5 From Sune Kloppenborg Jeppesen 2005-01-18 12:29:54 0000 -------
*** Bug 78558 has been marked as a duplicate of this bug. ***

------- Comment #6 From Sune Kloppenborg Jeppesen 2005-01-18 12:47:48 0000 -------
Robin/Jasmin please provide a patch for 4.0.22 or we'll have to mark 4.1 stable
to fix this.

------- Comment #7 From Robin Johnson 2005-01-18 13:15:59 0000 -------
The patch here applies cleanly to the 4.0.

4.1 is package.masked still, for several reasons. It _will_ break the tree (needing massive revdep-rebuild, and many packages don't build against it yet).

------- Comment #8 From Sune Kloppenborg Jeppesen 2005-01-18 13:38:55 0000 -------
Robin/Solar if the patch is fine please apply it.

------- Comment #9 From Robert Coie (RETIRED) 2005-01-18 14:06:51 0000 -------
I think there's a slight typo in the attached patch, where we have two $ on 
the $MYSQL_CNF assignment.  Applied to 4.0.23-r1 and 4.1.8-r1.

------- Comment #10 From Sune Kloppenborg Jeppesen 2005-01-18 22:33:24 0000 -------
Thx rac, but please don't close security bugs as we also handle stable marking.

Arches please test and mark stable 4.0.23-r1.

------- Comment #11 From Olivier Crete 2005-01-18 23:51:53 0000 -------
stable on x86

------- Comment #12 From Thierry Carrez (RETIRED) 2005-01-19 01:44:10 0000 -------
I vote for a GLSA since mysqlaccess is an admin tool in PATH.

------- Comment #13 From Sune Kloppenborg Jeppesen 2005-01-19 01:51:12 0000 -------
I vote for a GLSA on this one too.

------- Comment #14 From Markus Rothe 2005-01-19 05:22:02 0000 -------
stable on ppc64

------- Comment #15 From Gustavo Zacarias (RETIRED) 2005-01-19 07:26:39 0000 -------
stable on sparc.

------- Comment #16 From Ernst Herzberg 2005-01-19 08:25:50 0000 -------
STOP!
http://bugs.gentoo.org/show_bug.cgi?id=78678

------- Comment #17 From Thierry Carrez (RETIRED) 2005-01-19 09:11:36 0000 -------
I don't think the patch from 4.0.23 to 4.0.23-r1 broke it, it must be something
between 4.0.22 and 4.0.23 itself.

Back to ebuild status, uncalling arches and setting 78678 as blocker

------- Comment #18 From Robin Johnson 2005-01-19 13:13:07 0000 -------
crap
there is another bug in 4.0.23 as well.
http://bugs.mysql.com/bug.php?id=7515

It's broken in 4.0.23 and 4.1.8, so I've put 4.0.23 back as ~arch for all values of arch.

I'll see about backporting CAN-2005-0004 to 4.0.22.

------- Comment #19 From Robin Johnson 2005-01-19 15:22:03 0000 -------
Ok, lets try this again. mysql-4.0.22-r2 is in the tree as ~arch, and contains
the security fix.

------- Comment #20 From Sune Kloppenborg Jeppesen 2005-01-19 22:49:23 0000 -------
Thx Robin for backporting.

Arches please test and mark mysql-4.0.22-r2 stable

------- Comment #21 From Markus Rothe 2005-01-19 23:38:17 0000 -------
stable on ppc64.. once more.

.. I should have noticed this ..

------- Comment #22 From Gustavo Zacarias (RETIRED) 2005-01-20 07:26:38 0000 -------
4.0.22-r2 stable on sparc.

------- Comment #23 From Olivier Crete 2005-01-20 09:50:24 0000 -------
stable on x86 too... this bug looks pretty bad for our testing... (myself
included..). Could we do something to improve our QA on this sort of thing?

------- Comment #24 From Bryan Østergaard (RETIRED) 2005-01-20 10:22:29 0000 -------
4.0.22-r2 stable on alpha.

------- Comment #25 From Robin Johnson 2005-01-20 11:25:42 0000 -------
tester:
The libtool glitch didn't show up as I strongly suspect most devs are using the new libtool where it's bypassed.

------- Comment #26 From francesco riosa 2005-01-20 16:48:29 0000 -------
Created an attachment (id=49070) [details]
4.1.9 ebuild patches ewarn

really sorry for the typo signaled in #9 by Robert Coie

the patch signaled in #18 From Robin Johnson for mysql 4.0 reside at 
http://mysql.bkbits.net:8080/mysql-4.0/patch@1.2014
and is shorter than 100 rows

the one for mysql 4.1 include fix for MySQL Bugs: #7297: "Date decoding
trouble" but I was unable to apply to 4.1.8. It was already applied ???

so the motive to write this message has been dropped, to not trash (hoping not
to trash your ;) completely my time I've modified the 4.1.8-r1 ebuild to build
4.1.9.

changes are :
1) Added documentation for upgrade, and removed corrispondent TODO, you have
already experienced my english so please read and correct errors if there are.
Moved wait time out from warning() and modified wait time
2) modified again mysqld_safe patch, IMHO you can valutate to remove this
patch, the checks it do always fall into the chosen behaviour, it move often,
and is executed at startup only.
3) thrssl patch is not needed anymore, commented it

compiled with all useflag on but "debug" and "ruby"
included files:

# tar -ztf my-stuff-4.1.9.tar.gz
mysql-4.1.9.ebuild
4.1.8-r1_4.1.9.patch
files/digest-mysql-4.1.9
files/mysql-4.1.9-mysqld-safe-sh.diff

and a final note: mysql generally compile with -O3 optimization using -Os
should be evaluated at least on amd64 and x86, the executabe is 10% smaller and
I bet the cache hit increase more than that 10%, but this is argument for
another thread.

------- Comment #27 From Luca Barbato 2005-01-21 12:20:39 0000 -------
4.0.22-r2 stable on ppc.

------- Comment #28 From Simon Stelling (RETIRED) 2005-01-21 13:24:36 0000 -------
amd64 done

------- Comment #29 From Luke Macken (RETIRED) 2005-01-23 14:10:21 0000 -------
GLSA 200501-33

ia64/arm/hppa/s390/mips, please mark stable to benefit from GLSA.

------- Comment #30 From Joshua Kinard 2005-02-06 20:31:37 0000 -------
mips stable.

------- Comment #31 From Francesco R. (RETIRED) 2005-02-15 06:54:03 0000 -------
MySQL AB today released version 4.1.10 that fix this bug too

------- Comment #32 From René Nussbaumer 2005-06-26 05:30:47 0000 -------
Already stable on hppa

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug