MySQL-3.23.54: Suggested upgrade.

Jesse Tie-Ten-Quee <[email protected]>
Newsgroups gmane.linux.lfs.security
Organization http://linuxfromscratch.org
Message-ID <[email protected]>
Yo,

http://security.e-matters.de/advisories/042002.html

"We have discovered two flaws within the MySQL server that can be used by
any MySQL user to crash the server. Furthermore one of the flaws can be
used to bypass the MySQL password check or to execute arbitrary code with
the privileges of the user running mysqld. 

We have also discovered an arbitrary size heap overflow within the mysql
client library and another vulnerability that allows to write '\0' to any
memory address. Both flaws could allow DOS attacks against or arbitrary
code execution within anything linked against libmysqlclient."

I missed this yesterday as Billy did the version increment in BLFS
bugzilla and so I had no idea there were security issues untill I was reading
LWN.  Just finished upgrading.. no problems :)

-- 
Jesse Tie-Ten-Quee  ( highos at linuxfromscratch dot org )
-- 
Unsubscribe: send email to [email protected]
and put 'unsubscribe lfs-security' in the subject header of the message
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.