English | Deutsch | Español | Português
 UserID:
 Passwd:
new user
 About:   Dedicated  | Advanced  | Standard  | Recurring  | No Risk  | Desktop  | Basic  | Single  | Security Seal  | FAQ
  Price/Feature Summary  | Order  | New Vulnerabilities  | Confidentiality  | Vulnerability Search
 Vulnerability   
Search   
    Search 76783 CVE descriptions
and 40246 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.56795
Category:Trustix Local Security Checks
Title:Trustix Security Advisory TSLSA-2006-0028 (kernel, mysql)
Summary:Trustix Security Advisory TSLSA-2006-0028 (kernel, mysql)
Description:
The remote host is missing updates announced in
advisory TSLSA-2006-0028.

kernel < TSL 3.0 >
- New Upstream.
- SECURITY Fix: Memory leak in __setlease in fs/locks.c allows
attackers to cause a denial of service (memory consumption) via
unspecified actions related to an uninitialised return value,
aka slab leak.
- lease_init in fs/locks.c allows attackers to cause a denial of
service (fcntl_setlease lockup) via actions that cause lease_init
to free a lock that might not have been allocated on the stack.

The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the names CVE-2006-1859 and CVE-2006-1860 to these issue.

mysql < TSL 3.0 > < TSL 2.2 > < TSEL 2 >
- SECURITY Fix: Stefano Di Paola has reported some vulnerabilities in
MySQL, which can be exploited by malicious users to disclose
potentially sensitive information and compromise a vulnerable system.
- The check_connection function in sql_parse.cc in MySQL allows remote
attackers to read portions of memory via a username without a trailing
null byte, which causes a buffer over-read.
- sql_parse.cc in MySQL allows remote attackers to obtain sensitive
information via a COM_TABLE_DUMP request with an incorrect packet
length, which includes portions of memory in an error message.

The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the names CVE-2006-1516 and CVE-2006-1517 to these issues.

Solution:
Update your system with the packages as indicated in
the referenced security advisory.

http://www.securityspace.com/smysecure/catid.html?in=TSLSA-2006-0028

Risk factor : Medium
Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2006-1859
http://www.mandriva.com/security/advisories?name=MDKSA-2006:123
SuSE Security Announcement: SUSE-SA:2006:042 (Google Search)
http://www.novell.com/linux/security/advisories/2006_42_kernel.html
http://www.trustix.org/errata/2006/0028
http://www.ubuntu.com/usn/usn-302-1
BugTraq ID: 18033
http://www.securityfocus.com/bid/18033
http://www.vupen.com/english/advisories/2006/1767
http://secunia.com/advisories/20083
http://secunia.com/advisories/20716
http://secunia.com/advisories/21045
http://secunia.com/advisories/21179
XForce ISS Database: linux-locks-setlease-dos(26438)
http://xforce.iss.net/xforce/xfdb/26438
Common Vulnerability Exposure (CVE) ID: CVE-2006-1860
BugTraq ID: 17943
http://www.securityfocus.com/bid/17943
http://www.osvdb.org/25425
XForce ISS Database: linux-locks-lease-init-dos(26437)
http://xforce.iss.net/xforce/xfdb/26437
Common Vulnerability Exposure (CVE) ID: CVE-2006-1516
Bugtraq: 20060502 MySQL Anonymous Login Handshake - Information Leakage. (Google Search)
http://www.securityfocus.com/archive/1/archive/1/432733/100/0/threaded
Bugtraq: 20060516 UPDATE: [ GLSA 200605-13 ] MySQL: Information leakage (Google Search)
http://www.securityfocus.com/archive/1/archive/1/434164/100/0/threaded
http://www.wisec.it/vulns.php?page=7
http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html
Debian Security Information: DSA-1071 (Google Search)
http://www.debian.org/security/2006/dsa-1071
Debian Security Information: DSA-1073 (Google Search)
http://www.debian.org/security/2006/dsa-1073
Debian Security Information: DSA-1079 (Google Search)
http://www.debian.org/security/2006/dsa-1079
http://www.gentoo.org/security/en/glsa/glsa-200605-13.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2006:084
http://www.redhat.com/support/errata/RHSA-2006-0544.html
http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.599377
http://sunsolve.sun.com/search/document.do?assetkey=1-26-236703-1
SuSE Security Announcement: SUSE-SR:2006:012 (Google Search)
http://www.novell.com/linux/security/advisories/2006-06-02.html
SuSE Security Announcement: SUSE-SA:2006:036 (Google Search)
http://lists.suse.com/archive/suse-security-announce/2006-Jun/0011.html
http://www.ubuntulinux.org/support/documentation/usn/usn-283-1
Cert/CC Advisory: TA07-072A
http://www.us-cert.gov/cas/techalerts/TA07-072A.html
BugTraq ID: 17780
http://www.securityfocus.com/bid/17780
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9918
http://www.vupen.com/english/advisories/2006/1633
http://www.vupen.com/english/advisories/2007/0930
http://www.vupen.com/english/advisories/2008/1326/references
http://securitytracker.com/id?1016017
http://secunia.com/advisories/19929
http://secunia.com/advisories/20002
http://secunia.com/advisories/20073
http://secunia.com/advisories/20076
http://secunia.com/advisories/20223
http://secunia.com/advisories/20241
http://secunia.com/advisories/20253
http://secunia.com/advisories/20333
http://secunia.com/advisories/20424
http://secunia.com/advisories/20457
http://secunia.com/advisories/20625
http://secunia.com/advisories/20762
http://secunia.com/advisories/24479
http://secunia.com/advisories/29847
http://securityreason.com/securityalert/840
XForce ISS Database: mysql-login-packet-info-disclosure(26236)
http://xforce.iss.net/xforce/xfdb/26236
Common Vulnerability Exposure (CVE) ID: CVE-2006-1517
Bugtraq: 20060502 MySQL COM_TABLE_DUMP Information Leakage and Arbitrary commandexecution. (Google Search)
http://www.securityfocus.com/archive/1/archive/1/432734/100/0/threaded
http://www.wisec.it/vulns.php?page=8
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11036
http://www.osvdb.org/25228
http://securitytracker.com/id?1016016
http://securityreason.com/securityalert/839
XForce ISS Database: mysql-sqlparcecc-information-disclosure(26228)
http://xforce.iss.net/xforce/xfdb/26228
CopyrightCopyright (c) 2006 E-Soft Inc. http://www.securityspace.com

This is only one of 40246 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.

New User Registration
Email:
UserID:
Passwd:
Please email me your monthly newsletters, informing the latest services, improvements & surveys.
Please email me a vulnerability test announcement whenever a new test is added.
   Privacy
Registered User Login
 
UserID:   
Passwd:  

 Forgot userid or passwd?
Email/Userid:




Home | About Us | Contact Us | Partner Programs | Developer APIs | Privacy | Mailing Lists | Abuse
Security Audits | Managed DNS | Network Monitoring | Site Analyzer | Internet Research Reports
Web Probe | Whois

© 1998-2014 E-Soft Inc. All rights reserved.