Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 93081 - dev-db/mysql: Non-existent '--user' Error
Summary: dev-db/mysql: Non-existent '--user' Error
Status: RESOLVED INVALID
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Other
: High normal (vote)
Assignee: Gentoo Security
URL: http://securitytracker.com/alerts/200...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2005-05-18 08:56 UTC by Jean-François Brunette (RETIRED)
Modified: 2005-05-19 00:44 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Jean-François Brunette (RETIRED) gentoo-dev 2005-05-18 08:56:36 UTC
Version(s): prior to 4.1.12, 5.0.5
Description:  A vulnerability was reported in MySQL. The database server may run with incorrect privileges.

If the 'mysqld' process is started with the '--user=[non_existent_user]' command line configuration option, it will run with the privileges of the calling user instead of providing an error message.

Lachlan Mulcahy reported this vulnerability.
Impact:  The software may run with the incorrect permissions.
Solution:  The vendor has issued a fixed version (4.1.12), available at:

http://dev.mysql.com/downloads/

The pending version 5.0.5 will also include the fix.
Comment 1 Thierry Carrez (RETIRED) gentoo-dev 2005-05-18 09:10:19 UTC
This is a bug alright... but can't see how it can be exploited by an attacker
without dumb-user being in the loop.
Comment 2 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-05-18 10:45:09 UTC
Pulling in mysql-bugs to advise.  
Comment 3 Robin Johnson archtester Gentoo Infrastructure gentoo-dev Security 2005-05-18 17:43:05 UTC
4.1.12 is in the tree already
and I agree with Koon in that it can't be exploited without PEBKAC.
Comment 4 Thierry Carrez (RETIRED) gentoo-dev 2005-05-19 00:44:06 UTC
It's an already fixed bug, not a vulnerability. Reopen if you disagree.