Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 452938 - <dev-db/mysql-5.1.67 is affected by CVE-2012-5611 (remote expliot, pass auth)
Summary: <dev-db/mysql-5.1.67 is affected by CVE-2012-5611 (remote expliot, pass auth)
Status: RESOLVED DUPLICATE of bug 445602
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2013-01-19 10:52 UTC by Alex V. Koval
Modified: 2013-01-19 16:29 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alex V. Koval 2013-01-19 10:52:48 UTC
Hello,

I've been waiting for several days for new MySQL release after latest huge security holes found (CVE-2012-5611). More info at:
 * http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html

------------
This vulnerability is not remotely exploitable without authentication, i.e., may not be exploited over a network without the need for a username and password.
------------

it is being said that it has been silently patched in 5.1.67 community version. BUT, after waiting several days I don't see either GLSA for that, neither the updated package. May be I am looking at wrong place? please advice.
Comment 1 Alex V. Koval 2013-01-19 10:54:15 UTC
correct quote:

--------------------
2 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without the need for a username and password
--------------------
Comment 2 Alex Legler (RETIRED) archtester gentoo-dev Security 2013-01-19 16:29:50 UTC

*** This bug has been marked as a duplicate of bug 445602 ***