-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - -------------------------------------------------------------------------- CONECTIVA LINUX SECURITY ANNOUNCEMENT - -------------------------------------------------------------------------- PACKAGE : MySQL SUMMARY : Fixes for two mysql vulnerabilities DATE : 2005-04-20 10:36:00 ID : CLA-2005:947 RELEVANT RELEASES : 9, 10 - ------------------------------------------------------------------------- DESCRIPTION MySQL[1] is a very popular SQL database. This announcement fixes two vulnerabilities discovered in MySQL: 1.CAN-2004-0957[2] A local user which had grant privileges for a database whose name includes a "_" (underscore) caracter could grant privileges to other databases that have similar names, possibly allowing the user to conduct unauthorized activities. 2.CAN-2005-0004[3] A local user could overwrite arbitrary files or read temporary files via a symlink attack. SOLUTION We recommend that all MySQL users upgrade their packages as soon as possible. IMPORTANT: after the upgrade at Conectiva Linux 9, the mysql service must be restarted manually. In order to do that, run the following command as root: # /sbin/service mysql restart REFERENCES 1.http://www.mysql.com/products/mysql/ 2.http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0957 3.http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0004 UPDATED PACKAGES ftp://atualizacoes.conectiva.com.br/10/SRPMS/mysql-4.0.15-62448U10_3cl.src.rpm ftp://atualizacoes.conectiva.com.br/10/RPMS/libmysqlclient-devel-4.0.15-62448U10_3cl.i386.rpm ftp://atualizacoes.conectiva.com.br/10/RPMS/libmysqlclient-devel-static-4.0.15-62448U10_3cl.i386.rpm ftp://atualizacoes.conectiva.com.br/10/RPMS/libmysqlclient12-4.0.15-62448U10_3cl.i386.rpm ftp://atualizacoes.conectiva.com.br/10/RPMS/mysql-4.0.15-62448U10_3cl.i386.rpm ftp://atualizacoes.conectiva.com.br/10/RPMS/mysql-bench-4.0.15-62448U10_3cl.i386.rpm ftp://atualizacoes.conectiva.com.br/10/RPMS/mysql-client-4.0.15-62448U10_3cl.i386.rpm ftp://atualizacoes.conectiva.com.br/10/RPMS/mysql-doc-4.0.15-62448U10_3cl.i386.rpm ftp://atualizacoes.conectiva.com.br/9/SRPMS/MySQL-3.23.58-20507U90_4cl.src.rpm ftp://atualizacoes.conectiva.com.br/9/RPMS/MySQL-3.23.58-20507U90_4cl.i386.rpm ftp://atualizacoes.conectiva.com.br/9/RPMS/MySQL-bench-3.23.58-20507U90_4cl.i386.rpm ftp://atualizacoes.conectiva.com.br/9/RPMS/MySQL-client-3.23.58-20507U90_4cl.i386.rpm ftp://atualizacoes.conectiva.com.br/9/RPMS/MySQL-devel-3.23.58-20507U90_4cl.i386.rpm ftp://atualizacoes.conectiva.com.br/9/RPMS/MySQL-devel-static-3.23.58-20507U90_4cl.i386.rpm ftp://atualizacoes.conectiva.com.br/9/RPMS/MySQL-doc-3.23.58-20507U90_4cl.i386.rpm ADDITIONAL INSTRUCTIONS The apt tool can be used to perform RPM packages upgrades: - run: apt-get update - after that, execute: apt-get upgrade Detailed instructions regarding the use of apt and upgrade examples can be found at http://distro.conectiva.com.br/atualizacoes/#apt?idioma=en - ------------------------------------------------------------------------- All packages are signed with Conectiva's GPG key. The key and instructions on how to import it can be found at http://distro.conectiva.com.br/seguranca/chave/?idioma=en Instructions on how to check the signatures of the RPM packages can be found at http://distro.conectiva.com.br/seguranca/politica/?idioma=en - ------------------------------------------------------------------------- All our advisories and generic update instructions can be viewed at http://distro.conectiva.com.br/atualizacoes/?idioma=en - ------------------------------------------------------------------------- Copyright (c) 2004 Conectiva Inc. http://www.conectiva.com - ------------------------------------------------------------------------- subscribe: conectiva-updates-subscribe@xxxxxxxxxxxxxxxxxxxxxxxxxxx unsubscribe: conectiva-updates-unsubscribe@xxxxxxxxxxxxxxxxxxxxxxxxxxx -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.6 (GNU/Linux) Comment: For info see http://www.gnupg.org iD8DBQFCZm0j42jd0JmAcZARAhH2AKCHIkcAtpNAZ5841srEzSSuLn9sDQCgvj1s SFYpkTmd2k36JD4yW+Kr5ZA= =ItSC -----END PGP SIGNATURE-----