Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

MySQL Password Handler Buffer Overflow Vulnerability

Solution:
This issue has been reported to be addressed in MySQL 4.0.15.

Conectiva has released an advisory (CLA-2003:743), to address this issue. Users are advised to download and apply a relevant fixes as soon as possible. Further information relating to obtaining and applying appropriate fixes is available in the referenced advisory. Fixes are linked below. Conectiva has also released an advisory (CLSA-2003:764) for CLEE 1.0.

Trustix has released an advisory (TSLSA-2003-09-17) to address this issue. See referenced advisory for further details regarding the application of fixes. Fixes are linked below.

Debian has released advisory DSA 381-1 to address this issue. See referenced advisory for additional details.

Gentoo has released an advisory to address this issue. Gentoo updates can be applied with the following commands:

emerge sync
emerge \=dev-db/mysql/<mysql version>
emerge clean

OpenPKG has released an advisory to address this issue. Please see the attached advisory for detailed upgrade instructions.

EnGarde Secure Linux has released an advisory to address this issue. Please see the referenced advisory for detailed upgrade instructions.

Mandrake Linux has released an advisory to address this issue. Please see the referenced advisory for detailed upgrade instructions.

SuSE has released security advisory SuSE-SA:2003:042 to address this issue.

Turbolinux has released an advisory TLSA-2003-56 to address this issue. Please see the referenced advisory for detailed upgrade instructions.

Red Hat has released advisory RHSA-2003:281-01 to address this issue. See referenced advisory for additional information.

Red Hat has released advisory RHSA-2003:282-06 to address this issue in their Linux Enterprise software. Relevant patches are available through the Red Hat Network. See the referenced advisory for additional details.

SGI has released an advisory (20031002-01-U) pertaining to their ProPack Linux distribution. The advisory has been released in response to a number of RHSA advisories, and includes a patch (Patch 10027) containing updated RPM packages relating to 22 different BIDS.

Patch 10027 can be obtained via the following link:
http://support.sgi.com/

For information regarding how to obtain individual RPM packages included in Patch 10027, please see the attached advisory.

Sun has released an update to address this issue for RaQ550. Please see the referenced web page for more information.

Sun has released fixes for Sun Linux.

Sun has released an update to address this issue for Qube3. Please see the referenced web page for more information.


MySQL AB MySQL 4.1.0-0

MySQL AB MySQL 4.1.0.0-alpha

MySQL AB MySQL 3.23.36

MySQL AB MySQL 3.23.37

MySQL AB MySQL 3.23.44

MySQL AB MySQL 3.23.47

MySQL AB MySQL 3.23.48

MySQL AB MySQL 3.23.52

MySQL AB MySQL 3.23.53

MySQL AB MySQL 3.23.54

MySQL AB MySQL 3.23.54 a

MySQL AB MySQL 3.23.55

MySQL AB MySQL 3.23.56

MySQL AB MySQL 3.23.58

MySQL AB MySQL 4.0 .0

MySQL AB MySQL 4.0.1

MySQL AB MySQL 4.0.10

MySQL AB MySQL 4.0.11 -gamma

MySQL AB MySQL 4.0.11

MySQL AB MySQL 4.0.12

MySQL AB MySQL 4.0.13

MySQL AB MySQL 4.0.14

MySQL AB MySQL 4.0.2

MySQL AB MySQL 4.0.3

MySQL AB MySQL 4.0.4

MySQL AB MySQL 4.0.5

MySQL AB MySQL 4.0.5 a

MySQL AB MySQL 4.0.6

MySQL AB MySQL 4.0.7 -gamma

MySQL AB MySQL 4.0.7

MySQL AB MySQL 4.0.8 -gamma

MySQL AB MySQL 4.0.8

MySQL AB MySQL 4.0.9 -gamma

MySQL AB MySQL 4.0.9

Conectiva Linux 7.0

Conectiva Linux 8.0

Conectiva Linux 9.0







 

Privacy Statement
Copyright 2008, SecurityFocus