Gentoo Archives: gentoo-announce

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-announce@g.o
Subject: GLSA: mysqlcc (200303-7)
Date: Sun, 09 Mar 2003 00:27:21
Message-Id: 20030307155804.AB1B75761@mail2.tamperd.net
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - ---------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200303-7
6 - - ---------------------------------------------------------------------
7
8 PACKAGE : mysqlcc
9 SUMMARY : information leakage
10 DATE : 2003-03-07 16:03 UTC
11 EXPLOIT : local
12 VERSIONS AFFECTED : <0.8.9
13 FIXED VERSION : =>0.8.9
14 CVE :
15
16 - - ---------------------------------------------------------------------
17
18 Versions prior to 0.8.9 had all configuration and connection files
19 world readable.
20
21 SOLUTION
22
23 It is recommended that all Gentoo Linux users who are running
24 dev-db/mysqlcc upgrade to mysqlcc-0.8.10-r1 as follows:
25
26 emerge sync
27 emerge -u mysqlcc
28 emerge clean
29
30 - - ---------------------------------------------------------------------
31 aliz@g.o - GnuPG key is available at http://cvs.gentoo.org/~aliz
32 - - ---------------------------------------------------------------------
33 -----BEGIN PGP SIGNATURE-----
34 Version: GnuPG v1.2.1 (GNU/Linux)
35
36 iD8DBQE+aMK+fT7nyhUpoZMRAoq2AKDE1Xc6ler9UoKz2bVNtN4B4OMlLgCgtj4Y
37 a6RAI1/TyhIthLVSXYCcRj0=
38 =EL3y
39 -----END PGP SIGNATURE-----