Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.59638
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-1413-1)
Summary:The remote host is missing an update for the Debian 'mysql-dfsg, mysql-dfsg-4.1, mysql-dfsg-5.0' package(s) announced via the DSA-1413-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'mysql-dfsg, mysql-dfsg-4.1, mysql-dfsg-5.0' package(s) announced via the DSA-1413-1 advisory.

Vulnerability Insight:
Several vulnerabilities have been found in the MySQL database packages with implications ranging from unauthorized database modifications to remotely triggered server crashes. The Common Vulnerabilities and Exposures project identifies the following problems:

CVE-2007-2583

The in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40 allows context-dependent attackers to cause a denial of service (crash) via a crafted IF clause that results in a divide-by-zero error and a NULL pointer dereference. (Affects source version 5.0.32.)

CVE-2007-2691

MySQL does not require the DROP privilege for RENAME TABLE statements, which allows remote authenticated users to rename arbitrary tables. (All supported versions affected.)

CVE-2007-2692

The mysql_change_db function does not restore THD::db_access privileges when returning from SQL SECURITY INVOKER stored routines, which allows remote authenticated users to gain privileges. (Affects source version 5.0.32.)

CVE-2007-3780

MySQL could be made to overflow a signed char during authentication. Remote attackers could use specially crafted authentication requests to cause a denial of service. (Upstream source versions 4.1.11a and 5.0.32 affected.)

CVE-2007-3782

Phil Anderton discovered that MySQL did not properly verify access privileges when accessing external tables. As a result, authenticated users could exploit this to obtain UPDATE privileges to external tables. (Affects source version 5.0.32.)

CVE-2007-5925

The convert_search_mode_to_innobase function in ha_innodb.cc in the InnoDB engine in MySQL 5.1.23-BK and earlier allows remote authenticated users to cause a denial of service (database crash) via a certain CONTAINS operation on an indexed column, which triggers an assertion error. (Affects source version 5.0.32.)

For the old stable distribution (sarge), these problems have been fixed in version 4.0.24-10sarge3 of mysql-dfsg and version 4.1.11a-4sarge8 of mysql-dfsg-4.1.

For the stable distribution (etch), these problems have been fixed in version 5.0.32-7etch3 of the mysql-dfsg-5.0 packages.

We recommend that you upgrade your mysql packages.

Affected Software/OS:
'mysql-dfsg, mysql-dfsg-4.1, mysql-dfsg-5.0' package(s) on Debian 3.1, Debian 4.

Solution:
Please install the updated package(s).

CVSS Score:
6.0

CVSS Vector:
AV:N/AC:M/Au:S/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2007-2583
BugTraq ID: 23911
http://www.securityfocus.com/bid/23911
Debian Security Information: DSA-1413 (Google Search)
http://www.debian.org/security/2007/dsa-1413
http://www.exploit-db.com/exploits/30020
http://security.gentoo.org/glsa/glsa-200705-11.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2007:139
http://packetstormsecurity.com/files/124295/MySQL-5.0.x-Denial-Of-Service.html
http://www.osvdb.org/34734
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9930
http://www.redhat.com/support/errata/RHSA-2008-0364.html
http://secunia.com/advisories/25188
http://secunia.com/advisories/25196
http://secunia.com/advisories/25255
http://secunia.com/advisories/25389
http://secunia.com/advisories/25946
http://secunia.com/advisories/27155
http://secunia.com/advisories/27823
http://secunia.com/advisories/28838
http://secunia.com/advisories/30351
SuSE Security Announcement: SUSE-SR:2008:003 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.html
http://www.trustix.org/errata/2007/0017/
https://usn.ubuntu.com/528-1/
http://www.vupen.com/english/advisories/2007/1731
XForce ISS Database: mysql-if-dos(34232)
https://exchange.xforce.ibmcloud.com/vulnerabilities/34232
Common Vulnerability Exposure (CVE) ID: CVE-2007-2691
http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html
BugTraq ID: 24016
http://www.securityfocus.com/bid/24016
BugTraq ID: 31681
http://www.securityfocus.com/bid/31681
Bugtraq: 20070717 rPSA-2007-0143-1 mysql mysql-bench mysql-server (Google Search)
http://www.securityfocus.com/archive/1/473874/100/0/threaded
http://bugs.mysql.com/bug.php?id=27515
http://lists.mysql.com/announce/470
http://osvdb.org/34766
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9559
http://www.redhat.com/support/errata/RHSA-2007-0894.html
http://www.redhat.com/support/errata/RHSA-2008-0768.html
http://www.securitytracker.com/id?1018069
http://secunia.com/advisories/25301
http://secunia.com/advisories/26073
http://secunia.com/advisories/26430
http://secunia.com/advisories/31226
http://secunia.com/advisories/32222
http://www.vupen.com/english/advisories/2007/1804
http://www.vupen.com/english/advisories/2008/2780
XForce ISS Database: mysql-renametable-weak-security(34347)
https://exchange.xforce.ibmcloud.com/vulnerabilities/34347
Common Vulnerability Exposure (CVE) ID: CVE-2007-2692
BugTraq ID: 24011
http://www.securityfocus.com/bid/24011
http://www.mandriva.com/security/advisories?name=MDVSA-2008:028
http://bugs.mysql.com/bug.php?id=27337
http://osvdb.org/34765
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9166
http://www.securitytracker.com/id?1018070
http://secunia.com/advisories/28637
http://secunia.com/advisories/29443
http://www.ubuntu.com/usn/usn-588-1
XForce ISS Database: mysql-changedb-privilege-escalation(34348)
https://exchange.xforce.ibmcloud.com/vulnerabilities/34348
Common Vulnerability Exposure (CVE) ID: CVE-2007-3780
BugTraq ID: 25017
http://www.securityfocus.com/bid/25017
http://security.gentoo.org/glsa/glsa-200708-10.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2007:177
http://bugs.mysql.com/bug.php?id=28984
http://osvdb.org/36732
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11058
http://www.redhat.com/support/errata/RHSA-2007-0875.html
http://www.securitytracker.com/id?1018629
http://secunia.com/advisories/26498
http://secunia.com/advisories/26621
http://secunia.com/advisories/26710
http://secunia.com/advisories/26987
SuSE Security Announcement: SUSE-SR:2007:019 (Google Search)
http://www.novell.com/linux/security/advisories/2007_19_sr.html
http://www.vupen.com/english/advisories/2008/1000/references
Common Vulnerability Exposure (CVE) ID: CVE-2007-3782
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10563
http://securitytracker.com/id?1018663
Common Vulnerability Exposure (CVE) ID: CVE-2007-5925
BugTraq ID: 26353
http://www.securityfocus.com/bid/26353
https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00467.html
https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00475.html
http://lists.grok.org.uk/pipermail/full-disclosure/2007-November/067350.html
http://security.gentoo.org/glsa/glsa-200711-25.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2007:243
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11390
http://www.redhat.com/support/errata/RHSA-2007-1155.html
http://www.redhat.com/support/errata/RHSA-2007-1157.html
http://www.securitytracker.com/id?1018978
http://secunia.com/advisories/27568
http://secunia.com/advisories/27649
http://secunia.com/advisories/28025
http://secunia.com/advisories/28040
http://secunia.com/advisories/28099
http://secunia.com/advisories/28108
http://secunia.com/advisories/28128
http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.428959
http://www.ubuntu.com/usn/USN-1397-1
https://usn.ubuntu.com/559-1/
http://www.vupen.com/english/advisories/2007/3903
XForce ISS Database: mysql-hainnodb-dos(38284)
https://exchange.xforce.ibmcloud.com/vulnerabilities/38284
CopyrightCopyright (C) 2008 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.