Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 477474 (CVE-2013-3802) - <dev-db/mysql-{5.1.70,5.5.32,5.6.12}: multiple unspecified DoS (CPU July 2013) (CVE-2013-{3802,3804,3808})
Summary: <dev-db/mysql-{5.1.70,5.5.32,5.6.12}: multiple unspecified DoS (CPU July 2013...
Status: RESOLVED FIXED
Alias: CVE-2013-3802
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: http://www.oracle.com/technetwork/top...
Whiteboard: A3 [glsa]
Keywords: STABLEREQ
Depends on:
Blocks:
 
Reported: 2013-07-20 08:51 UTC by Agostino Sarubbo
Modified: 2013-08-29 09:12 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2013-07-20 08:51:51 UTC
Unspecified vulnerability in the MySQL Server component in Oracle
MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier
allows remote authenticated users to affect availability via unknown
vectors related to Full Text Search.

Unspecified vulnerability in the MySQL Server component in Oracle
MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier
allows remote authenticated users to affect availability via unknown
vectors related to Server Optimizer.

Unspecified vulnerability in the MySQL Server component in Oracle
MySQL 5.1.68 and earlier, 5.5.30 and earlier, and 5.6.10 allows remote
authenticated users to affect availability via unknown vectors related
to Server Options.

External References:

http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html#AppendixMSQL
Comment 1 Chris Reffett gentoo-dev Security 2013-07-20 11:46:54 UTC
@ago: the matrix also indicated a similar vulnerability in GIS (CVE-2013-1861), did you mean to exclude that one?

@maintainers: fixed versions (5.1.70, 5.5.32) are in the tree already, please ack a stable.
Comment 2 Jorge Manuel B. S. Vicetto Gentoo Infrastructure gentoo-dev 2013-07-20 17:34:17 UTC
(In reply to Chris Reffett from comment #1)
> @ago: the matrix also indicated a similar vulnerability in GIS
> (CVE-2013-1861), did you mean to exclude that one?
> 
> @maintainers: fixed versions (5.1.70, 5.5.32) are in the tree already,
> please ack a stable.

mysql-5.5 has not been stabled yet, so 5.5.32 will wait for the 5.5 stabilization bug.
Arches, please go ahead with 5.1.70.
Comment 3 Agostino Sarubbo gentoo-dev 2013-07-20 18:16:06 UTC
amd64 stable
Comment 4 Agostino Sarubbo gentoo-dev 2013-07-20 18:16:31 UTC
x86 stable
Comment 5 Agostino Sarubbo gentoo-dev 2013-07-21 15:36:13 UTC
alpha stable
Comment 6 Agostino Sarubbo gentoo-dev 2013-07-21 15:39:11 UTC
ia64 stable
Comment 7 Agostino Sarubbo gentoo-dev 2013-07-21 16:06:25 UTC
ppc64 stable
Comment 8 Agostino Sarubbo gentoo-dev 2013-07-21 17:23:39 UTC
ppc stable
Comment 9 Agostino Sarubbo gentoo-dev 2013-07-21 17:28:17 UTC
arm stable
Comment 10 Agostino Sarubbo gentoo-dev 2013-07-21 17:40:28 UTC
sh stable
Comment 11 Agostino Sarubbo gentoo-dev 2013-07-22 08:53:27 UTC
sparc stable
Comment 12 Jeroen Roovers gentoo-dev 2013-07-22 12:57:51 UTC
Um. Wow.
Comment 13 Jeroen Roovers gentoo-dev 2013-07-22 15:06:19 UTC
Stable for HPPA.
Comment 14 Agostino Sarubbo gentoo-dev 2013-08-06 12:32:18 UTC
s390 stable
Comment 15 GLSAMaker/CVETool Bot gentoo-dev 2013-08-27 02:58:52 UTC
CVE-2013-3808 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-3808):
  Unspecified vulnerability in the MySQL Server component in Oracle MySQL
  5.1.68 and earlier, 5.5.30 and earlier, and 5.6.10 allows remote
  authenticated users to affect availability via unknown vectors related to
  Server Options.

CVE-2013-3804 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-3804):
  Unspecified vulnerability in the MySQL Server component in Oracle MySQL
  5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote
  authenticated users to affect availability via unknown vectors related to
  Server Optimizer.

CVE-2013-3802 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-3802):
  Unspecified vulnerability in the MySQL Server component in Oracle MySQL
  5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote
  authenticated users to affect availability via unknown vectors related to
  Full Text Search.
Comment 16 Chris Reffett gentoo-dev Security 2013-08-28 22:55:12 UTC
GLSA request filed.
Comment 17 Chris Reffett gentoo-dev Security 2013-08-28 22:56:31 UTC
@maintainers: while we work on the GLSA, clean affected versions please.
Comment 18 GLSAMaker/CVETool Bot gentoo-dev 2013-08-29 09:12:03 UTC
This issue was resolved and addressed in
 GLSA 201308-06 at http://security.gentoo.org/glsa/glsa-201308-06.xml
by GLSA coordinator Sergey Popov (pinkbyte).