Gentoo Archives: gentoo-announce

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-announce@g.o
Subject: GLSA: mysql
Date: Sun, 15 Dec 2002 15:01:00
Message-Id: 20021215145640.D49E533762@mail1.tamperd.net
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - --------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200212-2.1
6 - - --------------------------------------------------------------------
7
8 PACKAGE : mysql
9 SUMMARY : remote DOS and arbitrary code execution
10 DATE    : 2002-12-15 12:12 UTC
11 EXPLOIT : remote
12
13 - - --------------------------------------------------------------------
14
15 The original advisory sent by me contained a typo (net-misc/freeswan
16 should have been dev-db/mysql). This re-issue has the correct text.
17
18 - From e-matters advisory:
19
20 "We have discovered two flaws within the MySQL server that can be used
21 by any MySQL user to crash the server. Furthermore one of the flaws can
22 be used to bypass the MySQL password check or to execute arbitrary code
23 with the privileges of the user running mysqld.
24    
25 We have also discovered an arbitrary size heap overflow within the mysql
26 client library and another vulnerability that allows to write '\0' to any
27 memory address. Both flaws could allow DOS attacks against or arbitrary
28 code execution within anything linked against libmysqlclient."
29
30 Read the full advisory at
31 http://security.e-matters.de/advisories/042002.html
32
33 SOLUTION
34
35 It is recommended that all Gentoo Linux users who are running
36 dev-db/mysql-3.23.53 and earlier update their systems as follows:
37
38 emerge rsync
39 emerge mysql
40 emerge clean
41
42 - - --------------------------------------------------------------------
43 aliz@g.o - GnuPG key is available at www.gentoo.org/~aliz
44 woodchip@g.o
45 - - --------------------------------------------------------------------
46 -----BEGIN PGP SIGNATURE-----
47 Version: GnuPG v1.2.1 (GNU/Linux)
48
49 iD8DBQE9/JgefT7nyhUpoZMRApRsAJ95aYUx7n0WEjXnBZlY8Zn7pYaLGwCfdGid
50 /yJgKoxAcgQMpT08CzM/tgI=
51 =kWbX
52 -----END PGP SIGNATURE-----