- - --------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200303-7 - - --------------------------------------------------------------------- PACKAGE : mysqlcc SUMMARY : information leakage DATE : 2003-03-07 16:03 UTC EXPLOIT : local VERSIONS AFFECTED : <0.8.9 :="" fixed version>0.8.9 CVE : - - --------------------------------------------------------------------- Versions prior to 0.8.9 had all configuration and connection files world readable. SOLUTION It is recommended that all Gentoo Linux users who are running dev-db/mysqlcc upgrade to mysqlcc-0.8.10-r1 as follows: emerge sync emerge -u mysqlcc emerge clean - - --------------------------------------------------------------------- aliz@gentoo.org - GnuPG key is available at - - --------------------------------------------------------------------- 0.8.9