MySQL-3.23.54: Suggested upgrade.
Jesse Tie-Ten-Quee <[email protected]>
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Organization | http://linuxfromscratch.org |
| Message-ID | <[email protected]> |
Yo, http://security.e-matters.de/advisories/042002.html "We have discovered two flaws within the MySQL server that can be used by any MySQL user to crash the server. Furthermore one of the flaws can be used to bypass the MySQL password check or to execute arbitrary code with the privileges of the user running mysqld. We have also discovered an arbitrary size heap overflow within the mysql client library and another vulnerability that allows to write '\0' to any memory address. Both flaws could allow DOS attacks against or arbitrary code execution within anything linked against libmysqlclient." I missed this yesterday as Billy did the version increment in BLFS bugzilla and so I had no idea there were security issues untill I was reading LWN. Just finished upgrading.. no problems :) -- Jesse Tie-Ten-Quee ( highos at linuxfromscratch dot org ) -- Unsubscribe: send email to [email protected] and put 'unsubscribe lfs-security' in the subject header of the message