Oval Definition:oval:org.mitre.oval:def:7877
Revision Date:2014-06-23Version:18
Title:DSA-1783 mysql-dfsg-5.0 -- multiple vulnerabilities
Description:Multiple vulnerabilities have been identified affecting MySQL, a relational database server, and its associated interactive client application. The Common Vulnerabilities and Exposures project identifies the following two problems: Kay Roepke reported that the MySQL server would not properly handle an empty bit-string literal in an SQL statement, allowing an authenticated remote attacker to cause a denial of service (a crash) in mysqld. This issue affects the oldstable distribution (etch), but not the stable distribution (lenny). Thomas Henlich reported that the MySQL commandline client application did not encode HTML special characters when run in HTML output mode (that is, "mysql --html ..."). This could potentially lead to cross-site scripting or unintended script privilege escalation if the resulting output is viewed in a browser or incorporated into a web site.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2008-3963
CVE-2008-4456
DSA-1783
Platform(s):Debian GNU/Linux 4.0
Debian GNU/Linux 5.0
Product(s):mysql-dfsg-5.0
Definition Synopsis
  • Release section
  • Debian GNU/Linux 5.0 is installed
  • AND Architecture section
  • Architecture independent section
  • Installed architecture is all
  • AND Packages section
  • mysql-client is earlier than 5.0.51a-24+lenny1
  • OR mysql-common is earlier than 5.0.51a-24+lenny1
  • OR mysql-server is earlier than 5.0.51a-24+lenny1
  • OR Architecture dependent section
  • Supported architectures section
  • Installed architecture is s390
  • OR Installed architecture is amd64
  • OR Installed architecture is sparc
  • OR Installed architecture is arm
  • OR Installed architecture is i386
  • OR Installed architecture is armel
  • OR Installed architecture is mips
  • OR Installed architecture is ia64
  • OR Installed architecture is alpha
  • OR Installed architecture is powerpc
  • OR Installed architecture is mipsel
  • OR Installed architecture is hppa
  • AND Packages section
  • libmysqlclient15-dev is earlier than 5.0.51a-24+lenny1
  • OR mysql-client-5.0 is earlier than 5.0.51a-24+lenny1
  • OR mysql-server-5.0 is earlier than 5.0.51a-24+lenny1
  • OR libmysqlclient15off is earlier than 5.0.51a-24+lenny1
  • OR Release section
  • Debian GNU/Linux 4.0 is installed.
  • AND Architecture section
  • Architecture independent section
  • Installed architecture is all
  • AND Packages section
  • mysql-client is earlier than 5.0.32-7etch10
  • OR mysql-common is earlier than 5.0.32-7etch10
  • OR mysql-server is earlier than 5.0.32-7etch10
  • OR Architecture dependent section
  • Supported architectures section
  • Installed architecture is s390
  • OR Installed architecture is amd64
  • OR Installed architecture is sparc
  • OR Installed architecture is arm
  • OR Installed architecture is i386
  • OR Installed architecture is ia64
  • OR Installed architecture is alpha
  • OR Installed architecture is powerpc
  • OR Installed architecture is mipsel
  • OR Installed architecture is hppa
  • AND Packages section
  • libmysqlclient15-dev is earlier than 5.0.32-7etch10
  • OR mysql-server-4.1 is earlier than 5.0.32-7etch10
  • OR mysql-client-5.0 is earlier than 5.0.32-7etch10
  • OR libmysqlclient15off is earlier than 5.0.32-7etch10
  • OR mysql-server-5.0 is earlier than 5.0.32-7etch10
  • BACK