Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 411503 (CVE-2012-2102) - <dev-db/mysql-5.1.62-r1: Two Unspecified Vulnerabilities (CVE-2012-2102)
Summary: <dev-db/mysql-5.1.62-r1: Two Unspecified Vulnerabilities (CVE-2012-2102)
Status: RESOLVED FIXED
Alias: CVE-2012-2102
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://secunia.com/advisories/48744/
Whiteboard: A3 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2012-04-10 18:34 UTC by Agostino Sarubbo
Modified: 2013-08-29 09:11 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2012-04-10 18:34:56 UTC
From secunia security advisory at $URL:

Description
Two vulnerabilities with unknown impacts have been reported in Oracle MySQL Server.

The vulnerabilities are caused due to unspecified errors. No further information is currently available.

The vulnerabilities are reported in versions prior to 5.5.22.


Solution
Update to version 5.5.22.

Original Advisory
http://dev.mysql.com/doc/refman/5.5/en/news-5-5-22.html
Comment 1 Agostino Sarubbo gentoo-dev 2012-04-10 18:36:34 UTC
@mysql team:

The advisory does not mention much, can you check if our version is affected or not?
Comment 2 Tim Sammut (RETIRED) gentoo-dev 2012-04-14 06:01:33 UTC
CVE assignment and more info in http://www.openwall.com/lists/oss-security/2012/04/13/7.
Comment 3 GLSAMaker/CVETool Bot gentoo-dev 2012-08-17 11:54:33 UTC
CVE-2012-2102 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2102):
  MySQL 5.1.x before 5.1.62 and 5.5.x before 5.5.22 allows remote
  authenticated users to cause a denial of service (assertion failure and
  mysqld abort) by deleting a record and using HANDLER READ NEXT.
Comment 4 GLSAMaker/CVETool Bot gentoo-dev 2013-08-29 09:11:51 UTC
This issue was resolved and addressed in
 GLSA 201308-06 at http://security.gentoo.org/glsa/glsa-201308-06.xml
by GLSA coordinator Sergey Popov (pinkbyte).