Pardus alert 2010-73 (mysql-server)
| From: | Eren Turkay <eren@pardus.org.tr> | |
| To: | pardus-security@pardus.org.tr | |
| Subject: | [Pardus-security] [PLSA 2010-73] MySQL: Privilege Escalation | |
| Date: | Fri, 4 Jun 2010 11:06:06 +0300 (EEST) | |
| Message-ID: | <20100604080606.C5205A7ABA1@lider.pardus.org.tr> |
------------------------------------------------------------------------ Pardus Linux Security Advisory 2010-73 security@pardus.org.tr ------------------------------------------------------------------------ Date: 2010-06-04 Severity: 3 Type: Remote ------------------------------------------------------------------------ Summary ======= A privilege escalation vulnerability has been fixed in MySQL, which can allow remote attackers to uninstall arbitrary plugins via the UNINSTALL PLUGIN command. Description =========== CVE-2010-1621: The mysql_uninstall_plugin function in sql/sql_plugin.cc in MySQL before 5.1.46 does not check privileges before uninstalling a plugin, which allows remote attackers to uninstall arbitrary plugins via the UNINSTALL PLUGIN command. CVE-2010-1626: MySQL before 5.1.46 allows local users to delete the data and index files of another user's MyISAM table via a symlink attack in conjunction with the DROP TABLE command, a different vulnerability than CVE-2008-4098 and CVE-2008-7247. Affected packages: Pardus 2009: mysql-server, all before 5.1.47-48-11 Resolution ========== There are update(s) for mysql-server. You can update them via Package Manager or with a single command from console: pisi up mysql-server References ========== * http://bugs.pardus.org.tr/show_bug.cgi?id=12991 ------------------------------------------------------------------------ _______________________________________________ Pardus-security mailing list Pardus-security@pardus.org.tr http://liste.pardus.org.tr/mailman/listinfo/pardus-security
