Oval Definition:oval:com.redhat.rhsa:def:20060544
Revision Date:2006-06-09Version:639
Title:RHSA-2006:0544: mysql security update (Important)
Description:MySQL is a multi-user, multi-threaded SQL database server. MySQL is a client/server implementation consisting of a server daemon (mysqld) and many different client programs and libraries.

  • A flaw was found in the way the MySQL mysql_real_escape() function escaped strings when operating in a multibyte character encoding. An attacker could provide an application a carefully crafted string containing invalidly-encoded characters which may be improperly escaped, leading to the injection of malicious SQL commands. (CVE-2006-2753)

  • An information disclosure flaw was found in the way the MySQL server processed malformed usernames. An attacker could view a small portion of server memory by supplying an anonymous login username which was not null terminated. (CVE-2006-1516)

  • An information disclosure flaw was found in the way the MySQL server executed the COM_TABLE_DUMP command. An authenticated malicious user could send a specially crafted packet to the MySQL server which returned random unallocated memory. (CVE-2006-1517)

  • A log file obfuscation flaw was found in the way the mysql_real_query() function creates log file entries. An attacker with the the ability to call the mysql_real_query() function against a mysql server can obfuscate the entry the server will write to the log file. However, an attacker needed to have complete control over a server in order to attempt this attack. (CVE-2006-0903)

    This update also fixes numerous non-security-related flaws, such as intermittent authentication failures.

    All users of mysql are advised to upgrade to these updated packages containing MySQL version 4.1.20, which is not vulnerable to these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2006-0903
    CVE-2006-1516
    CVE-2006-1517
    CVE-2006-2753
    CVE-2006-3081
    CVE-2006-4380
    RHSA-2006:0544
    RHSA-2006:0544-02
    RHSA-2006:0544-02
    Platform(s):Red Hat Enterprise Linux 4
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • mysql is earlier than 0:4.1.20-1.RHEL4.1
  • AND mysql is signed with Red Hat redhatrelease2 key
  • mysql-bench is earlier than 0:4.1.20-1.RHEL4.1
  • AND mysql-bench is signed with Red Hat redhatrelease2 key
  • mysql-devel is earlier than 0:4.1.20-1.RHEL4.1
  • AND mysql-devel is signed with Red Hat redhatrelease2 key
  • mysql-server is earlier than 0:4.1.20-1.RHEL4.1
  • AND mysql-server is signed with Red Hat redhatrelease2 key
  • BACK