Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 2 of 2
  1. #1
    Member equens's Avatar
    Join Date
    Feb 2002
    Posts
    256

    Default Multiple vulnerabilities have been identified in MySQL

    Multiple vulnerabilities have been identified in MySQL, which could be exploited by attackers to compromise a vulnerable system or gain knowledge of sensitive information.

    The first flaw is due to a buffer overflow error in the "sql_base.cc" script that does not properly handle specially crafted "COM_TABLE_DUMP" packets, which could be exploited by authenticated attackers to execute arbitrary commands.

    The second issue is due to an input validation error in the "sql_parse.cc" file that fails to properly validate "COM_TABLE_DUMP" packets, which could be exploited by attackers to cause portions of the memory to be disclosed in error messages.

    The third vulnerability is due to an input validation error in the "sql_parse.cc" script that fails to properly handle malformed login packets, which could be exploited by attackers to cause portions of the memory to be disclosed in error messages.

    Affected Products

    MySQL version 4.0.26 and prior
    MySQL version 4.1.18 and prior
    MySQL version 5.0.20 and prior
    MySQL version 5.1.9 and prior

    Solution

    Upgrade to MySQL version 5.0.21 :
    http://dev.mysql.com/downloads/

    References

    http://www.frsirt.com/english/advisories/2006/1633
    http://dev.mysql.com/doc/refman/5.0/en/news-5-0-21.html
    http://www.wisec.it/vulns.php?page=8
    http://www.wisec.it/vulns.php?page=7

    Credits

    Vulnerabilities reported by Stefano Di Paola

  2. #2
    Member celliott's Avatar
    Join Date
    Jan 2006
    Location
    United Kingdom
    Posts
    460

    Default

    Upgrading to 4.1.19 would also be a solution?

Similar Threads & Tags
Similar threads

  1. Multiple DoS Vulnerabilities in the BIND 9 Software
    By Kjette86 in forum cPanel and WHM Discussions
    Replies: 6
    Last Post: 09-13-2006, 07:15 AM
  2. cPanel Multiple Cross-Site Scripting Vulnerabilities
    By leorevenda in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 08-22-2006, 10:17 AM
  3. PHP: Multiple vulnerabilities - Severity: high
    By XPerties in forum cPanel and WHM Discussions
    Replies: 26
    Last Post: 06-07-2006, 12:25 PM
  4. MySQL AB MySQL Multiple Remote Vulnerabilities
    By Compubuster in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 03-18-2005, 01:58 AM
  5. WHM AutoPilot Multiple Vulnerabilities
    By fikse in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 12-30-2004, 02:39 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube