|
MySQL Mysql_real_connect Function Potential Remote Buffer Overflow Vulnerability
Solution: The vendor has reported that this issue will be addressed in the next release (4.0.21) of MySQL. Conectiva Linux has released advisory CLA-2004:892 along with fixes to address this and other issues. Please see the referenced advisory for further information. Debian has issued an advisory for this and other MySQL vulnerabilities. See DSA 562-1 in the reference section. Trustix Secure Linux has released advisory TSLSA-2004-0054 along with fixes to address this issue. Please see the referenced advisory for further information. Gentoo has released an advisory (GLSA 200410-22) to address various issues in MySQL. Please see the referenced advisory for more information. Gentoo users may carry out the following actions to update their computers: emerge sync emerge -pv ">=dev-db/mysql-4.0.21" emerge ">=dev-db/mysql-4.0.21" RedHat has released advisory RHSA-2004:611-04 along with fixes to address various issues in MySQL for RedHat Enterprise Linux operating systems. Please see the referenced advisory for further information. OpenPKG has released advisory OpenPKG-SA-2004.045 to address various issues in MySQL. Please see the referenced advisory for further information. Mandrake Linux has released advisory MDKSA-2004:119 along with fixes dealing with this and other issues. Please see the referenced advisory for more information. SuSE has released a security summary report (SUSE-SR:2004:001) to address this and other issues. The report indicates that a fix for this issue is available on the SuSE FTP server and also through the YaST Online Update utility. Customers are advised to peruse the referenced advisory for further details regarding obtaining and applying appropriate fixes. Ubuntu Linux has released advisory USN-32-1 along with fixes to address this, and other issues. Please see the referenced advisory for further information. RedHat Fedora has made an advisory available (FEDORA-2004-530) dealing with this and other issues. Please see the referenced advisory for more information. TurboLinux has released Security Announcement 17/Feb/2005 dealing with this and other issues; please see the reference section for more information. A Fedora Legacy advisory FLSA:2129 is available to address this issue in Red Hat Linux 7.3, Red Hat Linux 9, and Fedora Core 1 for the i386 architecture. Please see the referenced advisory for more information. MySQL AB MySQL 3.23.49
MySQL AB MySQL 3.23.52
MySQL AB MySQL 3.23.54 a
MySQL AB MySQL 3.23.56
MySQL AB MySQL 3.23.58
MySQL AB MySQL 4.0.18
MySQL AB MySQL 4.0.20
|
|
|
Privacy Statement |