Arch Linux

Please read this before reporting a bug:
https://wiki.archlinux.org/title/Bug_reporting_guidelines

Do NOT report bugs when a package is just outdated, or it is in the AUR. Use the 'flag out of date' link on the package page, or the Mailing List.

REPEAT: Do NOT report bugs for outdated packages!
Tasklist

FS#7103 - Warning on mysql

Attached to Project: Arch Linux
Opened by DaNiMoTh (DaNiMoTh) - Wednesday, 09 May 2007, 14:30 GMT
Last edited by Tobias Powalowski (tpowa) - Wednesday, 09 May 2007, 17:02 GMT
Task Type Bug Report
Category Security
Status Closed
Assigned To No-one
Architecture All
Severity Medium
Priority Normal
Reported Version 0.8 Voodoo
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 0
Private No

Details


------------------------------------------------------------
Arch Linux Security Warning ALSW 2007-#29
------------------------------------------------------------

Name: mysql
Date: 2007-05-09
Severity: Medium
Warning #: 2007-#29

------------------------------------------------------------

Product Background
===================
MySQL is a popular multi-threaded, multi-user SQL server.


Problem Background
===================
mu-b discovered a NULL pointer dereference in item_cmpfunc.cc when
processing certain types of SQL requests. Sec Consult also discovered
another NULL pointer dereference when sorting certain types of queries
on the database metadata.

Impact
==================
In both cases, a remote attacker could send a specially crafted SQL
request to the server, possibly resulting in a server crash. Note that
the attacker needs the ability to execute SELECT queries.

Workaround
==========

There is no known workaround at this time.

Problem Packages
===================
Package: mysql
Repo: current
Group: daemon
Unsafe: < 5.0.38
Safe: >= 5.0.38

Package Fix
===================
Upgrade to 5.0.38

===================

Unofficial ArchLinux Security Bug Tracker:
http://jjdanimoth.netsons.org/alsw.html

Reference(s)
===================
[ 1 ] Original Report
http://bugs.mysql.com/bug.php?id=27513
[ 2 ] CVE-2007-1420
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1420
This task depends upon

Closed by  Tobias Powalowski (tpowa)
Wednesday, 09 May 2007, 17:02 GMT
Reason for closing:  Fixed

Loading...