Bug#359701: Patches for CVE-2006-0903 "logging bypass via NULL char" available?

Christian Hammers <[email protected]>
Newsgroups gmane.linux.debian.devel.bugs.general,gmane.comp.db.mysql.packagers
Message-ID <[email protected]>
Hello

I've just got aware of the following security issue:

 CVE-2006-0903
 "MySQL 5.0.18 and earlier allows local users to bypass logging 
 mechanisms via SQL queries that contain the NULL character, 
 which are not properly handled by the mysql_real_query function."
 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0903

As http://bugs.mysql.com/ does currently not respond I cannot lookup
the corresponding MySQL bug report. Does anybody know if this issue
exists in 4.0 and 4.1 and if so, if patches exists that could be used
in the distributions security advisories?

BTW: I cannot find a reference to this in the official Changelog neither?

bye,

-christian-
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.