Summary: | dev-db/mysql <5.0.66 b'' Server DoS (CVE-2008-3963) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Alexey Vlasov <renton> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | luckyluke, mysql-bugs |
Priority: | High | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://bugs.mysql.com/bug.php?id=35658 | ||
Whiteboard: | A3 [glsa] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | 233567, 246652 | ||
Bug Blocks: |
Description
Alexey Vlasov
2008-09-09 10:52:12 UTC
Please open security relevant bugs in the Gentoo Security product of Bugzilla. CVE-2008-3963 has been assigned. Cannot reproduce on HPPA. dev-db/mysql-5.0.60-r1 gcc-4.2.4, CFLAGS=CXXFLAGS="-O2 -pipe -march=hppa2.0" tested with the SELECT b''; and SELECT x''; queries. but I can confirm it on x86_64. dev-db/mysql-5.0.60-r1 gcc-3.4.6-r2, CFLAGS=CXXFLAGS="-march=nocona -O2 -pipe -fforce-addr" hardened profile SELECT b''; will crash the server. all stable security: bump on GLSA for this. This issue was resolved and addressed in GLSA 201201-02 at http://security.gentoo.org/glsa/glsa-201201-02.xml by GLSA coordinator Tim Sammut (underling). |