Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Debian Lenny DSA-2057-1 Critical: MySQL Remote DoS and Buffer Overflow

debian
Calendar Grey June 7, 2010
Debian Logo
Tackling various concerns with MySQL database server referenced in Debian DSA-2057-1 notice pertaining to lenny stability.
Several vulnerabilities have been discovered in the MySQL database server

Summary

Several vulnerabilities have been discovered in the MySQL
database server.
The Common Vulnerabilities and Exposures project identifies the
following problems:


CVE-2010-1626

MySQL allows local users to delete the data and index files of another
user's MyISAM table via a symlink attack in conjunction with the DROP
TABLE command.


CVE-2010-1848

MySQL failed to check the table name argument of a COM_FIELD_LIST
command packet for validity and compliance to acceptable table name
standards. This allows an authenticated user with SELECT privileges on
one table to obtain the field definitions of any table in all other
databases and potentially of other MySQL instances accessible from the
server's file system.


CVE-2010-1849

MySQL could be tricked to read packets indefinitely if it received a
packet larger than the maximum size of one packet.
This results in high CPU usage and thus denial of service conditions.


CVE-2010-1850

MySQL was susceptible to a buffer-overflow attack due to a
failure to perform bounds checki...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: mysql-dfsg-5.0

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here