LWN.net Logo

mysql: arbitrary code execution

Package(s):mysql CVE #(s):CVE-2009-4484
Created:February 10, 2010 Updated:March 30, 2010
Description: From the Ubuntu advisory:

It was discovered that MySQL contained a buffer overflow when parsing ssl certificates. A remote attacker could send crafted requests and cause a denial of service or possibly execute arbitrary code. This issue did not affect Ubuntu 6.06 LTS and the default compiler options for affected releases should reduce the vulnerability to a denial of service. In the default installation, attackers would also be isolated by the AppArmor MySQL profile.

Alerts:
SuSE SUSE-SR:2010:007 2010-03-30
Debian DSA-1997-1 2010-02-14
Ubuntu USN-897-1 2010-02-10
Gentoo 201201-02 2012-01-05
Ubuntu USN-1397-1 2012-03-12

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds