Oval Definition:oval:com.redhat.rhsa:def:20050685
Revision Date:2005-10-05Version:502
Title:RHSA-2005:685: mysql security update (Low)
Description:MySQL is a multi-user, multi-threaded SQL database server. MySQL is a client/server implementation consisting of a server daemon (mysqld) and many different client programs and libraries.

An insecure temporary file handling bug was found in the mysql_install_db script. It is possible for a local user to create specially crafted files in /tmp which could allow them to execute arbitrary SQL commands during database installation. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-1636 to this issue.

These packages update mysql to version 4.1.12, fixing a number of problems. Also, support for SSL-encrypted connections to the database server is now provided.

All users of mysql are advised to upgrade to these updated packages.
Family:unixClass:patch
Status:Reference(s):CVE-2005-1636
RHSA-2005:685-01
Platform(s):Red Hat Enterprise Linux 4
Product(s):
Definition Synopsis
  • Red Hat Enterprise Linux 4 is installed
  • AND Package Information
  • mysql is earlier than 0:4.1.12-3.RHEL4.1
  • AND mysql is signed with Red Hat master key
  • OR
  • mysql-server is earlier than 0:4.1.12-3.RHEL4.1
  • AND mysql-server is signed with Red Hat master key
  • OR
  • mysql-bench is earlier than 0:4.1.12-3.RHEL4.1
  • AND mysql-bench is signed with Red Hat master key
  • OR
  • mysql-devel is earlier than 0:4.1.12-3.RHEL4.1
  • AND mysql-devel is signed with Red Hat master key
  • BACK