Description: | Description:
The remote host is missing an update to MySQL announced via advisory MDKSA-2004:119.
A number of problems have been discovered in the MySQL database server:
Jeroen van Wolffelaar discovered an insecure temporary file vulnerability in the mysqlhotcopy script when using the scp method (CVE-2004-0457).
Oleksandr Byelkin discovered that the ALTER TABLE ... RENAME would check the CREATE/INSERT rights of the old table rather than the new one (CVE-2004-0835).
Lukasz Wojtow discovered a buffer overrun in the mysql_real_connect function (CVE-2004-0836).
Dean Ellis discovered that multiple threads ALTERing the same (or different) MERGE tables to change the UNION can cause the server to crash or stall (CVE-2004-0837).
The updated MySQL packages have been patched to protect against these issues.
Affected versions: 10.0, 10.1, 9.2, Corporate Server 2.1
Solution: To upgrade automatically use MandrakeUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you.
http://www.securityspace.com/smysecure/catid.html?in=MDKSA-2004:119 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0457 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0835 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0836 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0837 http://bugs.mysql.com/bug.php?id=3270 http://bugs.mysql.com/bug.php?id=4017 http://bugs.mysql.com/bug.php?id=2408
Risk factor : Critical
CVSS Score: 10.0
|