Linux Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· Mageia 3 released
· Understanding Email Bounce Messages and more
· How to Prepare for Windows 8 Even Though Its Not Coming to Enterprises
· Microsoft Office Clone Updates Interface, Improves File Support
· Windows Firewall Control 4.0.0.0 released
· 10 amazing Linux desktop environments you've probably never seen
· Microsoft Office security flaw hits thousands in latest hacker attack
· Kubuntu 13.04 Raring Ringtail Review
· Windows Mobile 7 concept video shows why Microsoft dumped the platform
· Building a Thin Mini-ITX PC and more

Upcoming News
· SilverStone AR01 CPU Cooler Review @ Hardware Secrets
· PowerColor PCS+ HD7870 Gaming Video Card @ TechwareLabs
· Rosewill T600N Wireless Router Review @ ThinkComputers.org
· Google Play Music Review @ TechReviewSource.com
· Adata DashDrive Elite UE700 32GB Flash Drive Review @ Ninjalane
· News: HGST packs 1.5TB into 9.5-mm, three-platter Travelstar 5K1500 notebook drive
· Gigabyte GeForce GTX 650 Ti Boost OC WindForce 2X review
· Metro: Last Light Performance, Benchmarked
· Seidio Active Case Combo for HTC One Review @ TestFreaks
· Jawbone UP Wristband

Linux Compatibility
· Dell Dimension 9100
· CL-CAM50001 UPC=3700284609322
· DFE 520 TX
· nVidia GeForce4 MX 440
· Gore: Ultimate Soldier
· SMC2802W V2 wi-fi 54Mbps PCI card
· Wireless modem router N300
· Dell P780
· ASUS A7V8X
· BricsCAD for Linux

New Forum Topics
· shutdown link ?
by: estirwent
on: 2013-05-11 17:46
18 replies, 6397 views

· Laptop keyboard drank soda
by: Zenn
on: 2013-04-30 00:27
1 replies, 667 views

· connecting to to internet with ubuntu
by: Zenn
on: 2013-04-30 00:26
2 replies, 4526 views

· Need Linux-compatible PS/2 expansion card
by: Zenn
on: 2013-04-30 00:26
1 replies, 727 views

· irql_not_less_or_equal blue screen
by: Zenn
on: 2013-04-30 00:25
2 replies, 1121 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS
· Android

What's New
Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » November 2004 » USN-32-1: mysql vulnerabilities

USN-32-1: mysql vulnerabilities

Posted by Philipp Esselbach on: 11/25/2004 09:02 AM [ Print | 0 comment(s) ]

Updated MySQL packages are available for Ubuntu Linux 4.10

==========================================================
Ubuntu Security Notice USN-32-1 November 25, 2004
mysql-dfsg vulnerabilities
CAN-2004-0836, CAN-2004-0837, CAN-2004-0956, CAN-2004-0957
==========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 4.10 (Warty Warthog)

The following packages are affected:

mysql-server

The problem can be corrected by upgrading the affected package to version 4.0.20-2ubuntu1.1. In general, a standard system upgrade is sufficient to effect the necessary changes.




Details follow:

Several vulnerabilities have been discovered in the MySQL database server.

Lukasz Wojtow discovered a potential buffer overflow in the function mysql_real_connect(). A malicious name server could send specially crafted DNS packages which might result in execution of arbitrary code with the database server's privileges. However, it is believed that this bug cannot be exploited with the C Standard library (glibc) that Ubuntu uses. (CAN-2004-0836).

Dean Ellis noticed a flaw that allows an authorized MySQL user to cause a denial of service (crash or hang) via concurrent execution of certain statements (ALTER TABLE ... UNION=, FLUSH TABLES) on tables of type MERGE (CAN-2004-0837)

Some query strings containing a double quote (like MATCH ... AGAINST (' some " query' IN BOOLEAN MODE) ) that did not have a matching closing double quote caused a denial of service (server crash). Again, this is only exploitable by authorized mysql users. (CAN-2004-0956)

If a user was granted privileges to a database with a name containing an underscore ("_"), the user also gained the ability to grant privileges to other databases with similar names. (CAN-2004-0957)

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/mysql-dfsg_4.0.20-2ubuntu1.1.diff.gz
Size/MD5: 165384 7f507b594e9d5d9cd0a7adb2eca5d0c4
http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/mysql-dfsg_4.0.20-2ubuntu1.1.dsc
Size/MD5: 892 3afca4b6ec963ad9c239deb7df0c556d
http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/mysql-dfsg_4.0.20.orig.tar.gz
Size/MD5: 9760117 f092867f6df2f50b34b8065312b9fb2b

Architecture independent packages:

http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/mysql-common_4.0.20-2ubuntu1.1_all.deb
Size/MD5: 24012 44750442562ef128334a4ad1bcfef15c

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/libmysqlclient-dev_4.0.20-2ubuntu1.1_amd64.deb
Size/MD5: 2809794 a257ea0675c52c60b5d1ef3d5dfadebc
http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/libmysqlclient12_4.0.20-2ubuntu1.1_amd64.deb
Size/MD5: 304040 759952b1db7359f3f3b54d3d3bbc11ff
http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/mysql-client_4.0.20-2ubuntu1.1_amd64.deb
Size/MD5: 422102 d95d773d2479c3878a56248cdf2428de
http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/mysql-server_4.0.20-2ubuntu1.1_amd64.deb
Size/MD5: 3576654 4641b0ff8d06e82e21648352f01282d2

i386 architecture (x86 compatible Intel/AMD)

http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/libmysqlclient-dev_4.0.20-2ubuntu1.1_i386.deb
Size/MD5: 2773050 4717ed4d1405d70c6ede0056ee40e490
http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/libmysqlclient12_4.0.20-2ubuntu1.1_i386.deb
Size/MD5: 287018 5b18d12015bb46bf0c89e5bcc323b0a5
http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/mysql-client_4.0.20-2ubuntu1.1_i386.deb
Size/MD5: 396026 097eff3da7fc711a52473f62535c5d04
http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/mysql-server_4.0.20-2ubuntu1.1_i386.deb
Size/MD5: 3485608 0886647a564f4136efc4f72f694d22c3

powerpc architecture (Apple Macintosh G3/G4/G5)

http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/libmysqlclient-dev_4.0.20-2ubuntu1.1_powerpc.deb
Size/MD5: 3109072 b510d1c4a3a33da55cb3b97a612b2e19
http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/libmysqlclient12_4.0.20-2ubuntu1.1_powerpc.deb
Size/MD5: 307718 55738df34a3f30e34d702d8b804bb57a
http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/mysql-client_4.0.20-2ubuntu1.1_powerpc.deb
Size/MD5: 451512 7dcb7e811ff6a0a8a0528bbb49229ac1
http://security.ubuntu.com/ubuntu/pool/main/m/mysql-dfsg/mysql-server_4.0.20-2ubuntu1.1_powerpc.deb
Size/MD5: 3769072 f7274343ac2163a0ff377c9cad1ec07e


Bookmark and Share

« Half Life 2 Tweak Guide · ABIT AV8-3rd Eye Motherboard Review »

Linux Compatible » News » November 2004 » USN-32-1: mysql vulnerabilities
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2013 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition