Oval Definition:oval:com.redhat.rhsa:def:20050334
Revision Date:2005-03-28Version:502
Title:RHSA-2005:334: mysql security update (Important)
Description:MySQL is a multi-user, multi-threaded SQL database server.

This update fixes several security risks in the MySQL server.

Stefano Di Paola discovered two bugs in the way MySQL handles user-defined functions. A user with the ability to create and execute a user defined function could potentially execute arbitrary code on the MySQL server. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CAN-2005-0709 and CAN-2005-0710 to these issues.

Stefano Di Paola also discovered a bug in the way MySQL creates temporary tables. A local user could create a specially crafted symlink which could result in the MySQL server overwriting a file which it has write access to. The Common Vulnerabilities and Exposures project has assigned the name CAN-2005-0711 to this issue.

All users of the MySQL server are advised to upgrade to these updated packages, which contain fixes for these issues.
Family:unixClass:patch
Status:Reference(s):CVE-2005-0709
CVE-2005-0710
CVE-2005-0711
RHSA-2005:334-01
Platform(s):Red Hat Enterprise Linux 3
Red Hat Enterprise Linux 4
Product(s):
Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 3 is installed
  • AND
  • mysql is earlier than 0:3.23.58-15.RHEL3.1
  • AND mysql is signed with Red Hat master key
  • mysql-server is earlier than 0:3.23.58-15.RHEL3.1
  • AND mysql-server is signed with Red Hat master key
  • mysql-bench is earlier than 0:3.23.58-15.RHEL3.1
  • AND mysql-bench is signed with Red Hat master key
  • mysql-devel is earlier than 0:3.23.58-15.RHEL3.1
  • AND mysql-devel is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • mysql is earlier than 0:4.1.10a-1.RHEL4.1
  • AND mysql is signed with Red Hat master key
  • mysql-server is earlier than 0:4.1.10a-1.RHEL4.1
  • AND mysql-server is signed with Red Hat master key
  • mysql-bench is earlier than 0:4.1.10a-1.RHEL4.1
  • AND mysql-bench is signed with Red Hat master key
  • mysql-devel is earlier than 0:4.1.10a-1.RHEL4.1
  • AND mysql-devel is signed with Red Hat master key
  • BACK