English | Deutsch | Español | Português
 UserID:
 Passwd:
new user
 About:   Dedicated  | Advanced  | Standard  | Recurring  | No Risk  | Desktop  | Basic  | Single  | Security Seal  | FAQ
  Price/Feature Summary  | Order  | New Vulnerabilities  | Confidentiality  | Vulnerability Search
 Vulnerability   
Search   
    Search 75096 CVE descriptions
and 39644 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.57054
Category:Ubuntu Local Security Checks
Title:Ubuntu USN-303-1 (mysql-dfsg-5.0)
Summary:Ubuntu USN-303-1 (mysql-dfsg-5.0)
Description:
The remote host is missing an update to mysql-dfsg-5.0
announced via advisory USN-303-1.

A security issue affects the following Ubuntu releases:

Ubuntu 5.10
Ubuntu 6.06 LTS

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

An SQL injection vulnerability has been discovered when using less
popular multibyte encodings (such as SJIS, or BIG5) which contain
valid multibyte characters that end with the byte 0x5c (the
representation of the backslash character >>\

Many client libraries and applications use the non-standard, but
popular way of escaping the >>'
occurences of it with >>\'
affected encodings and does not interpret multibyte characters, and an
attacker supplies a specially crafted byte sequence as an input string
parameter, this escaping method would then produce a validly-encoded
character and an excess >>'
All subsequent characters would then be interpreted as SQL code, so
the attacker could execute arbitrary SQL commands.

The updated packages fix the mysql_real_escape_string() function to
escape quote characters in a safe way. If you use third-party software
which uses an ad-hoc method of string escaping, you should convert
them to use mysql_real_escape_string() instead, or at least use the
standard SQL method of escaping >>'>''

Solution:
The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 5.10:
libmysqlclient14 4.1.12-1ubuntu3.5
mysql-server-4.1 4.1.12-1ubuntu3.5

Ubuntu 6.06 LTS:
libmysqlclient15off 5.0.22-0ubuntu6.06
mysql-server-5.0 5.0.22-0ubuntu6.06

In general, a standard system upgrade is sufficient to effect the
necessary changes.

http://www.securityspace.com/smysecure/catid.html?in=USN-303-1

Risk factor : High
Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2006-2753
http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html
Debian Security Information: DSA-1092 (Google Search)
http://www.debian.org/security/2006/dsa-1092
http://www.gentoo.org/security/en/glsa/glsa-200606-13.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2006:097
http://www.redhat.com/support/errata/RHSA-2006-0544.html
http://www.trustix.org/errata/2006/0034/
http://www.ubuntulinux.org/support/documentation/usn/usn-303-1
http://www.ubuntu.com/usn/usn-288-3
Cert/CC Advisory: TA07-072A
http://www.us-cert.gov/cas/techalerts/TA07-072A.html
BugTraq ID: 18219
http://www.securityfocus.com/bid/18219
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10312
http://www.vupen.com/english/advisories/2006/2105
http://www.vupen.com/english/advisories/2007/0930
http://securitytracker.com/id?1016216
http://secunia.com/advisories/20365
http://secunia.com/advisories/20489
http://secunia.com/advisories/20541
http://secunia.com/advisories/20531
http://secunia.com/advisories/20562
http://secunia.com/advisories/20625
http://secunia.com/advisories/20712
http://secunia.com/advisories/24479
XForce ISS Database: mysql-ascii-sql-injection(26875)
http://xforce.iss.net/xforce/xfdb/26875
CopyrightCopyright (c) 2006 E-Soft Inc. http://www.securityspace.com

This is only one of 39644 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.

New User Registration
Email:
UserID:
Passwd:
Please email me your monthly newsletters, informing the latest services, improvements & surveys.
Please email me a vulnerability test announcement whenever a new test is added.
   Privacy
Registered User Login
 
UserID:   
Passwd:  

 Forgot userid or passwd?
Email/Userid:




Home | About Us | Contact Us | Partner Programs | Privacy | Mailing Lists | Abuse
Security Audits | Managed DNS | Network Monitoring | Site Analyzer | Internet Research Reports
Web Probe | Whois

© 1998-2014 E-Soft Inc. All rights reserved.