CVE-2009-4833 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-4833): MySQL Connector/NET before 6.0.4, when using encryption, does not verify SSL certificates during connection, which allows remote attackers to perform a man-in-the-middle attack with a spoofed SSL certificate.
Our in-tree version is extremly dusty. We have 1.0.9, the current one is 6.2.3!
I have bumped mysql-connector-net to 6.2.3 so this can probably be closed. All ebuilds were ~arch so I wouldn't have thought security would have been involved.
Thanks. Closing noglsa