Oval Definition:oval:com.redhat.rhsa:def:20071155
Revision Date:2007-12-18Version:639
Title:RHSA-2007:1155: mysql security update (Important)
Description:MySQL is a multi-user, multi-threaded SQL database server. MySQL is a client/server implementation consisting of a server daemon (mysqld), and many different client programs and libraries.

  • A flaw was found in a way MySQL handled symbolic links when database tables were created with explicit "DATA" and "INDEX DIRECTORY" options. An authenticated user could create a table that would overwrite tables in other databases, causing destruction of data or allowing the user to elevate privileges. (CVE-2007-5969)

  • A flaw was found in a way MySQL's InnoDB engine handled spatial indexes. An authenticated user could create a table with spatial indexes, which are not supported by the InnoDB engine, that would cause the mysql daemon to crash when used. This issue only causes a temporary denial of service, as the mysql daemon will be automatically restarted after the crash. (CVE-2007-5925)

    All mysql users are advised to upgrade to these updated packages, which contain backported patches to resolve these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2007-5925
    CVE-2007-5969
    RHSA-2007:1155
    RHSA-2007:1155-01
    RHSA-2007:1155-01
    Platform(s):Red Hat Enterprise Linux 4
    Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • mysql is earlier than 0:4.1.20-3.RHEL4.1.el4_6.1
  • AND mysql is signed with Red Hat redhatrelease2 key
  • mysql-bench is earlier than 0:4.1.20-3.RHEL4.1.el4_6.1
  • AND mysql-bench is signed with Red Hat redhatrelease2 key
  • mysql-devel is earlier than 0:4.1.20-3.RHEL4.1.el4_6.1
  • AND mysql-devel is signed with Red Hat redhatrelease2 key
  • mysql-server is earlier than 0:4.1.20-3.RHEL4.1.el4_6.1
  • AND mysql-server is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • mysql is earlier than 0:5.0.22-2.2.el5_1.1
  • AND mysql is signed with Red Hat redhatrelease2 key
  • mysql-bench is earlier than 0:5.0.22-2.2.el5_1.1
  • AND mysql-bench is signed with Red Hat redhatrelease2 key
  • mysql-devel is earlier than 0:5.0.22-2.2.el5_1.1
  • AND mysql-devel is signed with Red Hat redhatrelease2 key
  • mysql-server is earlier than 0:5.0.22-2.2.el5_1.1
  • AND mysql-server is signed with Red Hat redhatrelease2 key
  • mysql-test is earlier than 0:5.0.22-2.2.el5_1.1
  • AND mysql-test is signed with Red Hat redhatrelease2 key
  • BACK