Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.ANNOUNCE.SEC
  • [SECURITY] [DSA 2057-1] New mysql-dfsg-5.0 packages fix several vulnera

    From Giuseppe Iuculano@1:229/2 to All on Mon Jun 7 15:30:02 2010
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------ Debian Security Advisory DSA-2057-1 [email protected] http://www.debian.org/security/ Giuseppe Iuculano
    June 07, 2010 http://www.debian.org/security/faq
    - ------------------------------------------------------------------------

    Package : mysql-dfsg-5.0
    Vulnerability : several
    Problem type : remote
    Debian-specific: no
    CVE Id(s) : CVE-2010-1626 CVE-2010-1848 CVE-2010-1849 CVE-2010-1850

    Several vulnerabilities have been discovered in the MySQL
    database server.
    The Common Vulnerabilities and Exposures project identifies the
    following problems:


    CVE-2010-1626

    MySQL allows local users to delete the data and index files of another
    user's MyISAM table via a symlink attack in conjunction with the DROP
    TABLE command.


    CVE-2010-1848

    MySQL failed to check the table name argument of a COM_FIELD_LIST
    command packet for validity and compliance to acceptable table name
    standards. This allows an authenticated user with SELECT privileges on
    one table to obtain the field definitions of any table in all other
    databases and potentially of other MySQL instances accessible from the
    server's file system.


    CVE-2010-1849

    MySQL could be tricked to read packets indefinitely if it received a
    packet larger than the maximum size of one packet.
    This results in high CPU usage and thus denial of service conditions.


    CVE-2010-1850

    MySQL was susceptible to a buffer-overflow attack due to a
    failure to perform bounds checking on the table name argument of a COM_FIELD_LIST command packet. By sending long data for the table
    name, a buffer is overflown, which could be exploited by an
    authenticated user to inject malicious code.


    For the stable distribution (lenny), these problems have been fixed in
    version 5.0.51a-24+lenny4

    The testing (squeeze) and unstable (sid) distribution do not contain mysql-dfsg-5.0 anymore.

    We recommend that you upgrade your mysql-dfsg-5.0 package.

    Upgrade instructions
    - --------------------

    wget url
    will fetch the file for you
    dpkg -i file.deb
    will install the referenced file.

    If you are using the apt-get package manager, use the line for
    sources.list as given below:

    apt-get update
    will update the internal database
    apt-get upgrade
    will install corrected packages

    You may use an automated update by adding the resources from the
    footer to the proper configuration.


    Debian GNU/Linux 5.0 alias lenny
    - --------------------------------

    Debian (stable)
    - ---------------

    Stable updates are available for alpha, amd64, arm, armel, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc.

    Source archives:

    http://security.debian.org/pool/updates/main/m/mysql-dfsg-5.0/mysql-dfsg-5.0_5.0.51a-24+lenny4.diff.gz
    Size/MD5 checksum: 382688 98904282d9b1ba07a5fa441695c9cefd
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-5.0/mysql-dfsg-5.0_5.0.51a-24+lenny4.dsc
    Size/MD5 checksum: 1746 213d7a9655000a669a9262b68a645b84
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-5.0/mysql-dfsg-5.0_5.0.51a.orig.tar.gz
    Size/MD5 checksum: 17946664 6fae978908ad5eb790fa3f24f16dadba

    Architecture independent packages:

    http://security.debian.org/pool/updates/main/m/mysql-dfsg-5.0/mysql-client_5.0.51a-24+lenny4_all.deb
    Size/MD5 checksum: 53012 7b2c03b1e86bb4634bb65b7fd65a8ce0
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-5.0/mysql-server_5.0.51a-24+lenny4_all.deb
    Size/MD5 checksum: 55208 0059173c20f96569e532f34e8d8e6d3d
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-5.0/mysql-common_5.0.51a-24+lenny4_all.deb
    Size/MD5 checksum: 61784 165889f524b9cd317462910f34871652

    alpha architecture (DEC Alpha)

    http://security.debian.org/pool/updates/main/m/mysql-dfsg-5.0/libmysqlclient15-dev_5.0.51a-24+lenny4_alpha.deb
    Size/MD5 checksum: 9069806 dbf1efe0f87962a0ce24c3c2026f08fe
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-5.0/mysql-client-5.0_5.0.51a-24+lenny4_alpha.deb
    Size/MD5 checksum: 8921072 4109cdb9b571b8384e22990f049077e5
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-5.0/mysql-server-5.0_5.0.51a-24+lenny4_alpha.deb
    Size/MD5 checksum: 28367370 1f7b2cbe390dc19230b83aac2b427a1c
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-5.0/libmysqlclient15off_5.0.51a-24+lenny4_alpha.deb
    Size/MD5 checksum: 2017406 121ad24e4ef9408540b34f4c954ea03a

    amd64 architecture (AMD x86_64 (AMD64))

    http://security.debian.org/pool/updates/main/m/mysql-dfsg-5.0/libmysqlclient15-dev_5.0.51a-24+lenny4_amd64.deb
    Size/MD5 checksum: 7586258 dbffd3dcb28daa3070b68f0ee268d6b3
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-5.0/mysql-server-5.0_5.0.51a-24+lenny4_amd64.deb
    Size/MD5 checksum: 27296900 030ee9c14fbb373617e77158fb56c40f
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-5.0/mysql-client-5.0_5.0.51a-24+lenny4_amd64.deb
    Size/MD5 checksum: 8207020 233dde7fe1c8d16757862037b7f8c551
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-5.0/libmysqlclient15off_5.0.51a-24+lenny4_amd64.deb
    Size/MD5 checksum: 1905200 8296b7de029b8208828981d151ad7013

    arm architecture (ARM)

    http://security.debian.org/pool/updates/main/m/mysql-dfsg-5.0/mysql-server-5.0_5.0.51a-24+lenny4_arm.deb
    Size/MD5 checksum: 26227842 f2e1a010442bd1b007aa1b12192e507c
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-5.0/libmysqlclient15-dev_5.0.51a-24+lenny4_arm.deb
    Size/MD5 checksum: 7158596 b06eb5f03ef7cbc2bdbda36d5f286411
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-5.0/mysql-client-5.0_5.0.51a-24+lenny4_arm.deb
    Size/MD5 checksum: 7614948 a3e30a83a7a314001445b0dd39415516
    http://security.debian.org/pool/updates/main/m/mysql-dfsg-5.0/libmysqlclient15off_5.0.51a-24+lenny4_arm.deb
    Size/MD5 checksum: 1779078 69f97725b1aa16018a8b59e3f3723568

    armel architecture (ARM EABI)


    [continued in next message]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)
  • Who's Online

  • Recent Visitors

    • Krenn
      Sat Jun 6 11:38:56 2026
      from Sydney, Nsw via Telnet
    • Furryboy
      Sat Jun 6 10:56:29 2026
      from Romania, Galati via SSH
    • Centurion
      Fri Jun 5 22:28:01 2026
      from Berea, Ohio via Telnet
    • Ab Cadd
      Fri Jun 5 17:52:51 2026
      from Sheboygan, Wi via Telnet
    • Gwylbert
      Fri Jun 5 06:28:52 2026
      from Sydney, Nsw via Telnet
    • Centurion
      Thu Jun 4 23:42:23 2026
      from Berea, Ohio via Telnet
    • Michal Wronka
      Thu Jun 4 23:19:58 2026
      from Wroclaw, Poland via Telnet
    • Michal Wronka
      Thu Jun 4 23:17:20 2026
      from Wroclaw, Poland via SSH
  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 715
    Nodes: 16 (2 / 14)
    Uptime: 144:12:02
    Calls: 12,089
    Calls today: 2
    Files: 15,000
    Messages: 6,517,483

© >>> Magnum BBS <<<, 2026