Bug 119442 - CAN-2004-0381 mysqlbug temporary file vulnerability
Summary: CAN-2004-0381 mysqlbug temporary file vulnerability
Alias: None
Product: Red Hat Enterprise Linux 3
Classification: Red Hat
Component: mysql
Version: 3.0
Hardware: All
OS: Linux
Target Milestone: ---
Assignee: Tom Lane
QA Contact: David Lawrence
Keywords: Security
: 125992 (view as bug list)
Depends On:
TreeView+ depends on / blocked
Reported: 2004-03-30 15:45 UTC by Mark J. Cox
Modified: 2013-07-03 03:00 UTC (History)
3 users (show)

Clone Of:
Last Closed: 2004-10-20 19:41:28 UTC

Attachments (Terms of Use)

External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2004:569 normal SHIPPED_LIVE Low: mysql security update 2004-10-20 04:00:00 UTC

Description Mark J. Cox 2004-03-30 15:45:06 UTC
mysqlbug script has temporary file vulnerability (uses /tmp) which
could allow an attacker to use a symlink attack to overwrite arbitrary
files as the person running mysqlbug.

Reported to bugtraq on Mar24th, minor issue to be fixed with next
mysql update.

Comment 1 Robert Scheck 2004-06-14 22:19:06 UTC
Mark, you only marked CAN-2004-0381 for this bug, but the vulnerability 
of CAN-2004-0388 is there, too.

Both CANs should be fixed with the patch from attachment #101129 [details]

Comment 2 Tom Lane 2004-06-15 19:31:01 UTC
*** Bug 125991 has been marked as a duplicate of this bug. ***

Comment 3 Tom Lane 2004-06-15 19:32:08 UTC
*** Bug 125992 has been marked as a duplicate of this bug. ***

Comment 4 Robert Scheck 2004-06-15 20:26:31 UTC
Sorry Tom, for making that additional unnecessary work (for me and for
you), but it seems so, that there are multiple/different views how a 
bug has to be marked in bugzilla for different distributions &  
versions, but okay...the onliest I would be happy, is to have those 2 
CANs fixed at all 4 currently supported distributions/versions at all 
needed architectures (RHEL 2.1, 3 and FC 1, 2) ;-)

Most of your colleagues assign for each affected distribution version 
a separate bug, so I followed this example - sorry again!

Comment 5 Mark J. Cox 2004-06-16 13:43:21 UTC
Reopening bug 125991; we usually do keep RHEL and FC separate; but not
split up the individual versions of RHEL/FC.

Comment 6 Tom Lane 2004-10-06 22:19:57 UTC
Fix is in mysql-3.23.58-2.2, slated for RHEL3 U4, and also in
3.23.58-11 and beyond for FC3.

Comment 7 Josh Bressers 2004-10-20 19:41:28 UTC
An errata has been issued which should help the problem 
described in this bug report. This report is therefore being 
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files, 
please follow the link below. You may reopen this bug report 
if the solution does not work for you.


Note You need to log in before you can comment on or make changes to this bug.