Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 12038 - mysql security vulnerabilities - server and programs linked against libmysqlclient
Summary: mysql security vulnerabilities - server and programs linked against libmysqlc...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: [OLD] Unspecified (show other bugs)
Hardware: All Linux
: Highest critical (vote)
Assignee: Gentoo Security
URL: http://security.e-matters.de/advisori...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2002-12-12 14:18 UTC by Bug Hunter
Modified: 2002-12-15 06:29 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Bug Hunter 2002-12-12 14:18:49 UTC
MySQL <= 3.23.53a
and
MySQL <= 4.0.5a

Are vulnerable to multiple security vulnerabilities

Fix: upgrade to 3.23.54
(apparently no fix for <=4.0.5a)

From the Security Advisory:

"We have discovered two flaws within the MySQL server that can be used by any
MySQL user to crash the server. Furthermore one of the flaws can be used to
bypass the MySQL password check or to execute arbitrary code with the privileges
of the user running mysqld.

We have also discovered an arbitrary size heap overflow within the mysql client
library and another vulnerability that allows to write '\0' to any memory
address. Both flaws could allow DOS attacks against or arbitrary code execution
within anything linked against libmysqlclient."
Comment 1 Daniel Ahlberg (RETIRED) gentoo-dev 2002-12-15 06:29:10 UTC
3.32.54 in portage and glsa sent. Thanks for reporting this!