LWN.net Logo

mysql: multiple vulnerabilities

Package(s):mysql CVE #(s):CVE-2009-4028 CVE-2009-4030
Created:January 18, 2010 Updated:January 14, 2013
Description:

From the Mandriva advisory:

The vio_verify_callback function in viosslfactories.c in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41, when OpenSSL is used, accepts a value of zero for the depth of X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary SSL-based MySQL servers via a crafted certificate, as demonstrated by a certificate presented by a server linked against the yaSSL library (CVE-2009-4028).

MySQL 5.1.x before 5.1.41 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL data home directory, related to incorrect calculation of the mysql_unpacked_real_data_home value. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4098 and CVE-2008-2079 (CVE-2009-4030).

Alerts:
SUSE SUSE-SR:2010:021 2010-11-16
SuSE SUSE-SR:2010:011 2010-05-10
SuSE SUSE-SR:2010:007 2010-03-30
rPath rPSA-2010-0014-1 2010-03-07
Debian DSA-1997-1 2010-02-14
Mandriva MDVSA-2010:012 2010-01-17
Mandriva MDVSA-2010:011 2010-01-17
Red Hat RHSA-2010:0109-01 2010-02-16
CentOS CESA-2010:0109 2010-03-01
CentOS CESA-2010:0110 2010-02-17
Red Hat RHSA-2010:0110-01 2010-02-16
Ubuntu USN-897-1 2010-02-10
Gentoo 201201-02 2012-01-05
Ubuntu USN-1397-1 2012-03-12

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds