MySQL COM_CHANGE_USER Password Length Account Compromise Vulnerability

Solution:
EnGarde has released updated fixes. The original fixes did not address the COM_TABLE_DUMP vulnerability (BID 6368). The upgraded packages now include fixes for this vulnerability.

Gentoo Linux has released an advisory. Users who have installed dev-db/mysql-3.23.53 and earlier are urged to update their systems by issuing the following commands:

emerge rsync
emerge mysql
emerge clean

OpenPKG has released an advisory (OpenPKG-SA-2002.013) which addresses this issue. Please see the attached advisory for details on fixing this issue on systems using OpenPKG.

Conectiva Linux and Debian have released advisories. Information about obtaining and applying fixes can be found in the referenced advisories.

SuSE has released an advisory (SuSE-SA:2003:003) which addresses this issue. Please see the attached advisory for details on obtaining and applying fixes.

Veritas has released an advisory and updated feature and maintenance packs to address this issue.

This issue has been addressed in MySQL 3.23.54.


MySQL AB MySQL 3.22.32

MySQL AB MySQL 3.23.10

MySQL AB MySQL 3.23.22

MySQL AB MySQL 3.23.23

MySQL AB MySQL 3.23.24

MySQL AB MySQL 3.23.25

MySQL AB MySQL 3.23.26

MySQL AB MySQL 3.23.27

MySQL AB MySQL 3.23.28

MySQL AB MySQL 3.23.29

MySQL AB MySQL 3.23.3

MySQL AB MySQL 3.23.30

MySQL AB MySQL 3.23.31

MySQL AB MySQL 3.23.32

MySQL AB MySQL 3.23.33

MySQL AB MySQL 3.23.34

MySQL AB MySQL 3.23.36

MySQL AB MySQL 3.23.37

MySQL AB MySQL 3.23.38

MySQL AB MySQL 3.23.39

MySQL AB MySQL 3.23.4

MySQL AB MySQL 3.23.40

MySQL AB MySQL 3.23.41

MySQL AB MySQL 3.23.42

MySQL AB MySQL 3.23.43

MySQL AB MySQL 3.23.44

MySQL AB MySQL 3.23.45

MySQL AB MySQL 3.23.46

MySQL AB MySQL 3.23.47

MySQL AB MySQL 3.23.48

MySQL AB MySQL 3.23.49

MySQL AB MySQL 3.23.5

MySQL AB MySQL 3.23.50

MySQL AB MySQL 3.23.51

MySQL AB MySQL 3.23.52

MySQL AB MySQL 3.23.53

MySQL AB MySQL 3.23.53 a

MySQL AB MySQL 3.23.8

MySQL AB MySQL 3.23.9

Veritas Software NetBackup Advanced Reporter 3.4

Veritas Software NetBackup Advanced Reporter 4.5 FP3

Veritas Software NetBackup Global Data Manager 4.5 FP1

Veritas Software NetBackup Advanced Reporter 4.5 FP1

Veritas Software NetBackup Advanced Reporter 4.5 FP2

Veritas Software NetBackup Global Data Manager 4.5 MP1

Veritas Software NetBackup Global Data Manager 4.5 FP2

Veritas Software NetBackup Global Data Manager 4.5 MP3

Veritas Software NetBackup Advanced Reporter 4.5 MP3

Veritas Software NetBackup Global Data Manager 4.5 FP3

Veritas Software NetBackup Global Data Manager 4.5

Veritas Software NetBackup Advanced Reporter 4.5 MP2

Veritas Software NetBackup Global Data Manager 4.5 MP2

Veritas Software NetBackup Advanced Reporter 4.5

Veritas Software NetBackup Advanced Reporter 4.5 MP1


 

Privacy Statement
Copyright 2010, SecurityFocus