Bug 151051
Summary: | CAN-2005-0710 MySQL security attacks via user-defined functions in C (CAN-2005-0709) | ||
---|---|---|---|
Product: | Red Hat Enterprise Linux 3 | Reporter: | Bastien Nocera <bnocera> |
Component: | mysql | Assignee: | Tom Lane <tgl> |
Status: | CLOSED ERRATA | QA Contact: | David Lawrence <dkl> |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | 3.0 | CC: | bressers, hhorak, security-response-team, tao |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2005-03-28 19:44:49 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Bastien Nocera
2005-03-14 14:02:57 UTC
Tom, I'm a bit confused. Can you verify is this affects mysql 3. I was under the impression from your comments the other day that it does not. Thanks The notice from MySQL AB said that it affected 4.0.x and later; I assumed from that that 3.x didn't have the issue, which may have been overoptimistic. I'm not sure that they are still supporting 3.x at all. MySQL has now confirmed that the bugs also exist in 3.x, so we will need to do something about a back-patch ... for both RHEL3 and AS2.1. Back-patch created in mysql-3.23.58-15.RHEL3.1 for RHEL3 and mysql-3.23.58-1.72.2 for AS2.1. *** Bug 151733 has been marked as a duplicate of this bug. *** An advisory has been issued which should help the problem described in this bug report. This report is therefore being closed with a resolution of ERRATA. For more information on the solution and/or where to find the updated files, please follow the link below. You may reopen this bug report if the solution does not work for you. http://rhn.redhat.com/errata/RHSA-2005-334.html The errata release is incomplete for RHEL-3, and does not include a patched mysql-server package... On RHEL3, mysql-server is part of "Extras", see bug 152437 for tracking. |