Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 466518 - (CVE-2008-4456) CVE-2008-4456 mysql: mysql command line client XSS flaw
CVE-2008-4456 mysql: mysql command line client XSS flaw
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
low Severity low
: ---
: ---
Assigned To: Red Hat Product Security
http://nvd.nist.gov/nvd.cfm?cvename=C...
impact=low,source=cve,reported=200810...
: Security
Depends On: 502169 512255 512257 516803
Blocks:
  Show dependency treegraph
 
Reported: 2008-10-10 13:50 EDT by Josh Bressers
Modified: 2016-03-04 07:43 EST (History)
8 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2013-04-24 00:20:50 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2009:1289 normal SHIPPED_LIVE Moderate: mysql security and bug fix update 2009-09-01 09:32:14 EDT
Red Hat Product Errata RHSA-2009:1461 normal SHIPPED_LIVE Important: Red Hat Application Stack v2.4 security and enhancement update 2009-09-23 17:38:40 EDT
Red Hat Product Errata RHSA-2010:0110 normal SHIPPED_LIVE Moderate: mysql security update 2010-02-16 11:27:21 EST

  None (edit)
Description Josh Bressers 2008-10-10 13:50:39 EDT
Cross-site scripting (XSS) vulnerability in the command-line client in MySQL 5.0.26 through 5.0.45, when the --html option is enabled, allows attackers to inject arbitrary web script or HTML by placing it in a database cell, which might be accessed by this client when composing an HTML document.

http://www.securityfocus.com/archive/1/archive/1/496842/100/0/threaded
http://www.securityfocus.com/archive/1/archive/1/496877/100/0/threaded
http://www.henlich.de/it-security/mysql-command-line-client-html-injection-vulnerability
http://bugs.mysql.com/bug.php?id=27884
http://secunia.com/advisories/32072
Comment 2 Jan Lieskovsky 2009-05-14 13:21:32 EDT
The issue has been rated as having low security impact, as this can only be a security flaw when all following conditions are met:

1) A database contains untrusted third party data.
2) A site uses the mysql command line tool with the --html option.
3) The resulting HTML output is placed and viewed on a web site the attacker    
   could use to launch a cross-site-scripting attack.
Comment 5 errata-xmlrpc 2009-09-02 05:45:30 EDT
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2009:1289 https://rhn.redhat.com/errata/RHSA-2009-1289.html
Comment 6 errata-xmlrpc 2009-09-02 08:10:03 EDT
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2009:1289 https://rhn.redhat.com/errata/RHSA-2009-1289.html
Comment 8 Vincent Danen 2009-09-04 17:18:37 EDT
This issue does affect Red Hat Enterprise Linux 3 and 4, however the Security Response Team has rated it has having low impact and may be addressed in a future update.
Comment 9 errata-xmlrpc 2009-09-23 17:39:01 EDT
This issue has been addressed in following products:

  Red Hat Web Application Stack for RHEL 5

Via RHSA-2009:1461 https://rhn.redhat.com/errata/RHSA-2009-1461.html
Comment 10 errata-xmlrpc 2010-02-16 11:27:44 EST
This issue has been addressed in following products:

  Red Hat Enterprise Linux 4

Via RHSA-2010:0110 https://rhn.redhat.com/errata/RHSA-2010-0110.html

Note You need to log in before you can comment on or make changes to this bug.