LWN.net Logo

OpenPKG alert OpenPKG-SA-2005.024 (mysql)

From:  OpenPKG <openpkg@openpkg.org>
To:  openpkg-announce@openpkg.org
Subject:  [OpenPKG-SA-2005.024] OpenPKG Security Advisory (mysql)
Date:  Sat, 3 Dec 2005 13:39:11 +0100

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ________________________________________________________________________ OpenPKG Security Advisory The OpenPKG Project http://www.openpkg.org/security.html http://www.openpkg.org openpkg-security@openpkg.org openpkg@openpkg.org OpenPKG-SA-2005.024 03-Dec-2005 ________________________________________________________________________ Package: mysql Vulnerability: buffer overflow, arbitrary code execution OpenPKG Specific: no Affected Releases: Affected Packages: Corrected Packages: OpenPKG CURRENT <= mysql-4.1.12-20050617 >= mysql-4.1.13-20050721 OpenPKG 2.5 N.A. N.A. OpenPKG 2.4 <= mysql-4.1.12-2.4.0 >= mysql-4.1.12-2.4.1 Description: According to a security advisory from Reid Borsuk of Application Security Inc [0], a stack-based buffer overflow exists in the MySQL RDBMS [1]. The buffer overflow allows remote authenticated users who can create user-defined database functions to execute arbitrary code via a long "function_name" field. The Common Vulnerabilities and Exposures (CVE) project assigned the id CVE-2005-2558 [2] to the problem. ________________________________________________________________________ References: [0] http://www.appsecinc.com/resources/alerts/mysql/2005-002.... [1] http://www.mysql.com/ [2] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2558 ________________________________________________________________________ For security reasons, this advisory was digitally signed with the OpenPGP public key "OpenPKG <openpkg@openpkg.org>" (ID 63C4CB9F) of the OpenPKG project which you can retrieve from http://pgp.openpkg.org and hkp://pgp.openpkg.org. Follow the instructions on http://pgp.openpkg.org/ for details on how to verify the integrity of this advisory. ________________________________________________________________________ -----BEGIN PGP SIGNATURE----- Comment: OpenPKG <openpkg@openpkg.org> iD8DBQFDkZHYgHWT4GPEy58RAqseAKDSQf/+kOxsxm1qsLLm+ltjQx4xUQCfWpnw f3BRG7NLaRSz9W6POAZjC5o= =UotL -----END PGP SIGNATURE----- ______________________________________________________________________ The OpenPKG Project www.openpkg.org Project Announcement List openpkg-announce@openpkg.org


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds