Description: | Description:
The remote host is missing updates announced in advisory RHSA-2007:1155.
MySQL is a multi-user, multi-threaded SQL database server. MySQL is a client/server implementation consisting of a server daemon (mysqld), and many different client programs and libraries.
A flaw was found in a way MySQL handled symbolic links when database tables were created with explicit DATA and INDEX DIRECTORY options. An authenticated user could create a table that would overwrite tables in other databases, causing destruction of data or allowing the user to elevate privileges. (CVE-2007-5969)
A flaw was found in a way MySQL's InnoDB engine handled spatial indexes. An authenticated user could create a table with spatial indexes, which are not supported by the InnoDB engine, that would cause the mysql daemon to crash when used. This issue only causes a temporary denial of service, as the mysql daemon will be automatically restarted after the crash. (CVE-2007-5925)
All mysql users are advised to upgrade to these updated packages, which contain backported patches to resolve these issues.
Solution: Please note that this update is available via Red Hat Network. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date
http://rhn.redhat.com/errata/RHSA-2007-1155.html http://www.redhat.com/security/updates/classification/#important
Risk factor : High
CVSS Score: 7.1
|