GLSA: mysql (200303-14)

From: Daniel Ahlberg (alizat_private)
Date: Tue Mar 18 2003 - 10:12:56 PST

  • Next message: Daniel Ahlberg: "GLSA: man (200303-13)"

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - - ---------------------------------------------------------------------
    GENTOO LINUX SECURITY ANNOUNCEMENT 200303-14
    - - ---------------------------------------------------------------------
    
              PACKAGE : mysql
              SUMMARY : remote root exploit
                 DATE : 2003-03-18 18:12 UTC
              EXPLOIT : remote
    VERSIONS AFFECTED : <3.23.56
        FIXED VERSION : >=3.23.56
                  CVE : 
    
    - - ---------------------------------------------------------------------
    
    "This issue has been adressed in 3.23.56 (release build is started
    today), and some steps were taken to alleviate the threat.
    
    In particular, MySQL will no longer read config files that are
    world-writeable (and SELECT ... OUTFILE always creates world-writeable
    files). Also, unlike other options, for --user option the first one will
    have the precedence. So if --user is set in /etc/my.cnf (as it is
    recommended in the manual), datadir/my.cnf will not be able to override
    it."
    
    quote from:
    http://marc.theaimsgroup.com/?l=bugtraq&m=104739810523433&w=2
    
    SOLUTION
    
    It is recommended that all Gentoo Linux users who are running
    dev-db/mysql upgrade to mysql-3.23.56 as follows:
    
    emerge sync
    emerge mysql
    emerge clean
    
    - - ---------------------------------------------------------------------
    alizat_private - GnuPG key is available at http://cvs.gentoo.org/~aliz
    - - ---------------------------------------------------------------------
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.1 (GNU/Linux)
    
    iD8DBQE+d2GffT7nyhUpoZMRAiDNAJ9CABOwtIrF3njTkLBxCO2SdvtsugCeMqqH
    SSeumvMyzTQCfb0/C4I1nIU=
    =HMcb
    -----END PGP SIGNATURE-----
    



    This archive was generated by hypermail 2b30 : Tue Mar 18 2003 - 13:30:42 PST